First published: Fri Aug 09 2019(Updated: )
In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Business Intelligence and Reporting Tools | >=1.0.0<=4.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11776 is a vulnerability in Eclipse BIRT versions 1.0 to 4.7 that allows Reflected XSS in the URL parameter.
CVE-2019-11776 affects Eclipse BIRT versions 1.0 to 4.7, allowing an attacker to execute a payload in the victim's browser context.
The severity of CVE-2019-11776 is medium with a severity value of 6.1.
To fix CVE-2019-11776, update Eclipse BIRT to a version higher than 4.7.
The CWE ID for CVE-2019-11776 is 79.