CVE-2019-11776: XSS
Published Aug 9, 2019
·Updated
In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.
Affected Software
1 affected component
Eclipse Business Intelligence And Reporting Tools>=1.0.0<=4.7.0
Event History
Aug 9, 2019
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-11776?
CVE-2019-11776 is a vulnerability in Eclipse BIRT versions 1.0 to 4.7 that allows Reflected XSS in the URL parameter.
2
How does CVE-2019-11776 affect Eclipse BIRT?
CVE-2019-11776 affects Eclipse BIRT versions 1.0 to 4.7, allowing an attacker to execute a payload in the victim's browser context.
3
What is the severity of CVE-2019-11776?
The severity of CVE-2019-11776 is medium with a severity value of 6.1.
4
How can I fix CVE-2019-11776?
To fix CVE-2019-11776, update Eclipse BIRT to a version higher than 4.7.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-11776?
The CWE ID for CVE-2019-11776 is 79.