CVE-2019-13189: XSS
Published Aug 28, 2019
·Updated
In Knowage through 6.1.1, there is XSS via the starturl or userid field to the ChangePwdServlet page.
Affected Software
1 affected component
eng Knowage<6.4
Event History
Aug 28, 2019
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13189?
CVE-2019-13189 is classified as a medium severity vulnerability.
2
How do I fix CVE-2019-13189?
To fix CVE-2019-13189, ensure that you sanitize and validate user inputs in the start_url and user_id fields.
3
What type of vulnerability is CVE-2019-13189?
CVE-2019-13189 is an XSS (Cross-Site Scripting) vulnerability.
4
Which versions of Knowage are affected by CVE-2019-13189?
Knowage versions up to 6.1.1 are affected by CVE-2019-13189.
5
How can attackers exploit CVE-2019-13189?
Attackers can exploit CVE-2019-13189 by injecting malicious scripts through the start_url or user_id fields.