CVE-2019-13345: XSS
A vulnerability was found in cachemgr.cgi web module of Squid through 4.7 has XSS via the username or auth parameter.
Reference: https://bugs.squid-cache.org/showbug.cgi?id=4957 https://github.com/squid-cache/squid/pull/429
Other sources
The cachemgr.cgi web module of Squid through 4.7 has XSS via the username or auth parameter.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-13345?
CVE-2019-13345 is a vulnerability in the cachemgr.cgi web module of Squid through version 4.7 that allows for XSS attacks via the user_name or auth parameter.
What is the severity of CVE-2019-13345?
The severity of CVE-2019-13345 is high, with a CVSS score of 6.1.
How can I fix CVE-2019-13345?
To fix CVE-2019-13345, you should update Squid to version 4.8-1 or apply the appropriate security patches provided by the vendor.
Where can I find more information about CVE-2019-13345?
You can find more information about CVE-2019-13345 on the MITRE CVE database (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13345), the Debian LTS announcement (https://lists.debian.org/debian-lts-announce/2019/07/msg00006.html), and the Ubuntu security notice (https://ubuntu.com/security/notices/USN-4059-1).
What is the CWE classification of CVE-2019-13345?
CVE-2019-13345 is classified under CWE-79, which is the category for Cross-Site Scripting (XSS) vulnerabilities.