CVE-2019-16926
Last modified
CVE-2019-16926 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vulnerability. EPSS estimates a 0.82% chance of exploitation in the next 30 days.
Description
Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Flower Project | Flower | 1.0.0 |
References
- https://fatihhcelik.blogspot.com/2019/09/flower-100-has-xss-via-crafted-worker.htmlExploit, Third Party Advisory
- https://fatihhcelik.blogspot.com/2019/09/flower-100-has-xss-via-crafted-worker.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-16926?
How severe is CVE-2019-16926?
How do I fix CVE-2019-16926?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-16920Unauthenticated remote code execution occurs in D-Link produ…9.8
- CVE-2019-16921In the Linux kernel before 4.17, hns_roce_alloc_ucontext in …7.5
- CVE-2019-16922SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allo…5.3
- CVE-2019-16923kkcms 1.3 has jx.php?url= XSS.6.1
- CVE-2019-16924The Nulock application 1.5.0 for mobile devices sends a clea…8.8
- CVE-2019-16925Flower 0.9.3 has XSS via the name parameter in an @app.task …6.1
- CVE-2019-16927Xpdf 4.01.01 has an out-of-bounds write in the vertProfile p…5.5
- CVE-2019-16928Exim 4.92 through 4.92.2 allows remote code execution, a dif…9.8
- CVE-2019-16929Auth0 auth0.net before 6.5.4 has Incorrect Access Control be…7.5
- CVE-2019-1693A vulnerability in the WebVPN service of Cisco Adaptive Secu…6.5
- CVE-2019-16930Zcashd in Zcash before 2.0.7-3 allows discovery of the IP ad…5.3
- CVE-2019-16931A stored XSS vulnerability in the Visualizer plugin 3.3.0 fo…6.1
Are you affected by CVE-2019-16926?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
