CVE-2019-14298: XSS
Published Jul 27, 2019
·Updated
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx.
Affected Software
1 affected component
VEEAM ONE Reporter=9.5.0.3201
Event History
Jul 27, 2019
CVE Published
via MITRE·10:36 PM
Data Sourced
via MITRE·10:36 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2019-14298.
2
What is the severity of CVE-2019-14298?
The severity of CVE-2019-14298 is medium with a score of 5.4.
3
How does CVE-2019-14298 affect Veeam ONE Reporter?
CVE-2019-14298 affects Veeam ONE Reporter 9.5.0.3201.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2019-14298?
The CWE ID associated with CVE-2019-14298 is CWE-79.
5
Is there any reference material available for CVE-2019-14298?
Yes, you can find more information about CVE-2019-14298 at the following link: [CVE-2019-14298 Reference](https://www.exploit-db.com/exploits/46766).