CVE-2019-13274: XSS
Published Aug 27, 2019
·Updated
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
Affected Software
2 affected components
Xymon xymon<=4.3.28
Debian Debian Linux=8.0
Event History
Aug 27, 2019
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13274?
CVE-2019-13274 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-13274?
To fix CVE-2019-13274, upgrade Xymon to version 4.3.29 or later where the vulnerability has been addressed.
3
What software is affected by CVE-2019-13274?
CVE-2019-13274 affects Xymon version 4.3.28 and earlier, as well as Debian Linux 8.0.
4
What type of vulnerability is CVE-2019-13274?
CVE-2019-13274 is a cross-site scripting (XSS) vulnerability in the csvinfo CGI script.
5
How is CVE-2019-13274 exploited?
CVE-2019-13274 can be exploited by injecting malicious scripts into the db parameter, leading to unauthorized script execution in a user's browser.