First published: Thu Jul 11 2019(Updated: )
XSS exists in Ping Identity Agentless Integration Kit before 1.5.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Agentless Integration Kit | <1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-13564.
The severity of the CVE-2019-13564 vulnerability is medium with a CVSS score of 6.1.
The XSS vulnerability affects Ping Identity Agentless Integration Kit versions up to exclusive version 1.5.
To fix the XSS vulnerability in Ping Identity Agentless Integration Kit, update to a version that is equal to or greater than 1.5.
You can find more information about the CVE-2019-13564 vulnerability in the following references: [Link 1](http://packetstormsecurity.com/files/154274/Ping-Identity-Agentless-Integration-Kit-Cross-Site-Scripting.html), [Link 2](http://seclists.org/fulldisclosure/2019/Aug/33), [Link 3](https://github.com/sbaresearch/advisories/tree/public/2019/SBA-ADV-20190305-01_Ping_Identity_Agentless_Integration_Kit_Reflected_XSS).