First published: Sat Jul 27 2019(Updated: )
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam ONE Reporter | =9.5.0.3201 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14297 refers to a vulnerability in Veeam ONE Reporter 9.5.0.3201 that allows XSS attacks through a crafted Caption field.
The vulnerability in Veeam ONE Reporter 9.5.0.3201 allows an attacker to execute cross-site scripting (XSS) attacks by manipulating the Caption field in the Add/Edit Widget feature.
CVE-2019-14297 has a severity level of medium (5.4).
To fix CVE-2019-14297, it is recommended to update Veeam ONE Reporter to a version that addresses the vulnerability.
You can find more information about CVE-2019-14297 at the following link: https://www.exploit-db.com/exploits/46767