CVE-2019-1010147: XSS
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector is: Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. The fixed version is: 7.4 and later.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-1010147.
What is the title of the vulnerability?
The title of the vulnerability is Incorrect Access Control - Privileges Escalation in Yellowfin Smart Reporting.
What is the severity of CVE-2019-1010147?
The severity of CVE-2019-1010147 is medium with a CVSS score of 5.4.
How does CVE-2019-1010147 impact the system?
CVE-2019-1010147 allows an attacker to access admin functionality through the victim's browser and gain control over the browser.
What is the affected component of CVE-2019-1010147?
The affected component of CVE-2019-1010147 is MIAdminStyles.i4.
What is the attack vector of CVE-2019-1010147?
The attack vector of CVE-2019-1010147 is through typical victims.
Which software versions are affected by CVE-2019-1010147?
All versions prior to 7.3 of Yellowfin Smart Reporting and BMC Remedy Smart Reporting are affected by CVE-2019-1010147.
Is there a fix available for CVE-2019-1010147?
It is recommended to upgrade Yellowfin Smart Reporting to version 7.3 or newer to fix CVE-2019-1010147.
What is the Common Weakness Enumeration (CWE) ID of CVE-2019-1010147?
The CWE ID of CVE-2019-1010147 is 79, which stands for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
Where can I find more information about CVE-2019-1010147?
You can find more information about CVE-2019-1010147 at the following link: [https://drive.google.com/open?id=1sk5IklziyEggeWpWE4Wyk9xqa30CjNpS]