CVE-2019-14747: XSS
Published Aug 7, 2019
·Updated
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
Affected Software
1 affected component
Diaowen Dwsurvey<=2019-07-22
Event History
Aug 7, 2019
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14747?
CVE-2019-14747 is classified as a moderate severity vulnerability due to its ability to facilitate stored cross-site scripting attacks.
2
How do I fix CVE-2019-14747?
To fix CVE-2019-14747, upgrade to a version of DWSurvey released after July 22, 2019, where this vulnerability has been addressed.
3
What type of vulnerability is CVE-2019-14747?
CVE-2019-14747 is a stored cross-site scripting (XSS) vulnerability affecting DWSurvey.
4
What systems are affected by CVE-2019-14747?
CVE-2019-14747 affects all versions of DWSurvey up to and including 2019-07-22.
5
What is the impact of CVE-2019-14747?
The impact of CVE-2019-14747 includes the possibility for attackers to execute malicious scripts in the context of a user's browser.