CVE-2019-19249

CRITICALCVSS 9.8/10EPSS 1.24%

Last modified

CVE-2019-19249 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.. EPSS estimates a 1.24% chance of exploitation in the next 30 days.

Description

Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.24%

65.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
QuerytreeappQuerytree3.0.11Beta
QuerytreeappQuerytree3.0.13Beta
QuerytreeappQuerytree3.0.15Beta
QuerytreeappQuerytree3.0.17Beta
QuerytreeappQuerytree3.0.19Beta
QuerytreeappQuerytree3.0.21Beta
QuerytreeappQuerytree3.0.25Beta
QuerytreeappQuerytree3.0.27Beta
QuerytreeappQuerytree3.0.29Beta
QuerytreeappQuerytree3.0.31Beta
QuerytreeappQuerytree3.0.36Beta
QuerytreeappQuerytree3.0.39Beta
QuerytreeappQuerytree3.0.41Beta
QuerytreeappQuerytree3.0.43Beta
QuerytreeappQuerytree3.0.45Beta
QuerytreeappQuerytree3.0.49Beta
QuerytreeappQuerytree3.0.51Beta
QuerytreeappQuerytree3.0.53Beta
QuerytreeappQuerytree3.0.55Beta
QuerytreeappQuerytree3.0.57Beta
QuerytreeappQuerytree3.0.59Beta
QuerytreeappQuerytree3.0.61Beta
QuerytreeappQuerytree3.0.63Beta
QuerytreeappQuerytree3.0.65Beta
QuerytreeappQuerytree3.0.69Beta
QuerytreeappQuerytree3.0.71Beta
QuerytreeappQuerytree3.0.73Beta
QuerytreeappQuerytree3.0.76Beta
QuerytreeappQuerytree3.0.79Beta
QuerytreeappQuerytree3.0.83Beta
QuerytreeappQuerytree3.0.85Beta
QuerytreeappQuerytree3.0.88Beta
QuerytreeappQuerytree3.0.90Beta
QuerytreeappQuerytree3.0.92Beta
QuerytreeappQuerytree3.0.95Beta
QuerytreeappQuerytree3.0.97Beta
QuerytreeappQuerytree3.0.99Beta

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-19249?
Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.
How severe is CVE-2019-19249?
CVE-2019-19249 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.24% probability of exploitation in the next 30 days.
How do I fix CVE-2019-19249?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-19249?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST