CVE-2019-1010247: XSS
Published Jul 19, 2019
·Updated
ZmartZone IAM modauthopenidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/modauthopenidc.c, Line: 3109. The fixed version is: 2.3.10.2.
Affected Software
1 affected component
openidc Mod Auth Openidc<2.3.10.2
Remediation
Event History
Jul 19, 2019
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-1010247.
2
What is the severity level of CVE-2019-1010247?
The severity level of CVE-2019-1010247 is medium with a CVSS score of 6.1.
3
What is the impact of CVE-2019-1010247?
The impact of CVE-2019-1010247 is redirecting the user to a phishing page or interacting with the application on behalf of the user.
4
Which component is affected by CVE-2019-1010247?
The affected component of CVE-2019-1010247 is the file src/mod_auth_openidc.c on line 3109.
5
How can I fix CVE-2019-1010247?
To fix CVE-2019-1010247, upgrade to version 2.3.10.2 of ZmartZone IAM mod_auth_openidc.