CVE-2019-7250
Last modified
CVE-2019-7250 is a vulnerability of currently unknown severity. An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configuration panel may allow a malicious user to use both label text and references text to inject arbitrary JavaScript code (via SCRIPT elements, event handlers, etc.). EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configuration panel may allow a malicious user to use both label text and references text to inject arbitrary JavaScript code (via SCRIPT elements, event handlers, etc.). Since this code is stored by the plugin, the attacker may be able to target anyone who opens the configuration panel of the plugin.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cross Reference Project | Cross Reference | 36 |
References
- https://github.com/davidrthorn/cross_reference/issues/32Exploit, Third Party Advisory
- https://github.com/davidrthorn/cross_reference/issues/32Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-7250?
How severe is CVE-2019-7250?
How do I fix CVE-2019-7250?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-7240An issue was discovered in WinRing0x64.sys in Moo0 System Mo…7.2
- CVE-2019-7244An issue was discovered in kerneld.sys in AIDA64 before 5.99…7.2
- CVE-2019-7245An issue was discovered in GPU-Z.sys in TechPowerUp GPU-Z be…7.2
- CVE-2019-7246An issue was discovered in atillk64.sys in AMD ATI Diagnosti…6.7
- CVE-2019-7247An issue was discovered in AODDriver2.sys in AMD OverDrive. …9.8
- CVE-2019-7249In Keybase before 2.12.6 on macOS, the move RPC to the Helpe…
- CVE-2019-7251An Integer Signedness issue (for a return code) in the res_p…
- CVE-2019-7252Linear eMerge E3-Series devices have Default Credentials.
- CVE-2019-7253Linear eMerge E3-Series devices allow Directory Traversal.
- CVE-2019-7254Linear eMerge E3-Series devices allow File Inclusion.7.5
- CVE-2019-7255Linear eMerge E3-Series devices allow XSS.6.1
- CVE-2019-7256Linear eMerge E3-Series devices allow Command Injections.9.8
Are you affected by CVE-2019-7250?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
