First published: Sat Jul 27 2019(Updated: )
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam ONE | =9.5.0.3201 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-14298.
The severity of CVE-2019-14298 is medium with a score of 5.4.
CVE-2019-14298 affects Veeam ONE Reporter 9.5.0.3201.
The CWE ID associated with CVE-2019-14298 is CWE-79.
Yes, you can find more information about CVE-2019-14298 at the following link: [CVE-2019-14298 Reference](https://www.exploit-db.com/exploits/46766).