CVE-2019-13538: XSS
3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13538?
CVE-2019-13538 is classified as a medium severity vulnerability.
How do I fix CVE-2019-13538?
To fix CVE-2019-13538, upgrade CODESYS to version 3.5.16.0 or later.
What impact does CVE-2019-13538 have on CODESYS users?
CVE-2019-13538 allows for potentially manipulated library contents to be displayed or executed.
Is CVE-2019-13538 present in all versions of CODESYS?
CVE-2019-13538 affects all versions of CODESYS prior to 3.5.16.0.
What type of software does CVE-2019-13538 affect?
CVE-2019-13538 specifically affects the CODESYS Library Manager used by 3S-Smart Software Solutions.