CVE-2019-14297: XSS
Published Jul 27, 2019
·Updated
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.
Affected Software
1 affected component
VEEAM ONE Reporter=9.5.0.3201
Event History
Jul 27, 2019
CVE Published
via MITRE·10:36 PM
Data Sourced
via MITRE·10:36 PM
Description
Frequently Asked Questions
1
What is CVE-2019-14297?
CVE-2019-14297 refers to a vulnerability in Veeam ONE Reporter 9.5.0.3201 that allows XSS attacks through a crafted Caption field.
2
How does CVE-2019-14297 work?
The vulnerability in Veeam ONE Reporter 9.5.0.3201 allows an attacker to execute cross-site scripting (XSS) attacks by manipulating the Caption field in the Add/Edit Widget feature.
3
What is the severity level of CVE-2019-14297?
CVE-2019-14297 has a severity level of medium (5.4).
4
How can I fix CVE-2019-14297?
To fix CVE-2019-14297, it is recommended to update Veeam ONE Reporter to a version that addresses the vulnerability.
5
Where can I find more information about CVE-2019-14297?
You can find more information about CVE-2019-14297 at the following link: https://www.exploit-db.com/exploits/46767