CVE-2019-1578
Last modified
CVE-2019-1578 is a vulnerability of currently unknown severity. Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could execute arbitrary JavaScript code in the admin’s browser.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could execute arbitrary JavaScript code in the admin’s browser.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Minemeld | <= 0.9.60 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1578?
How severe is CVE-2019-1578?
How do I fix CVE-2019-1578?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-15774The nd-booking plugin before 2.5 for WordPress has a nopriv_…
- CVE-2019-15775The nd-learning plugin before 4.8 for WordPress has a nopriv…
- CVE-2019-15776The simple-301-redirects-addon-bulk-uploader plugin before 1…
- CVE-2019-15777The shapepress-dsgvo plugin before 2.2.19 for WordPress has …
- CVE-2019-15778The woo-variation-gallery plugin before 1.1.29 for WordPress…
- CVE-2019-15779The insta-gallery plugin before 2.4.8 for WordPress has no n…
- CVE-2019-15780The formidable plugin before 4.02.01 for WordPress has unsaf…9.8
- CVE-2019-15781The facebook-by-weblizar plugin before 2.8.5 for WordPress h…
- CVE-2019-15782WebTorrent before 0.107.6 allows XSS in the HTTP server via …
- CVE-2019-15783Lute-Tab before 2019-08-23 has a buffer overflow in pdf_prin…
- CVE-2019-15784Secure Reliable Transport (SRT) through 1.3.4 has a CSndULis…
- CVE-2019-15785FontForge 20190813 through 20190820 has a buffer overflow in…
Are you affected by CVE-2019-1578?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
