CVE-2019-15095: XSS
Published Aug 16, 2019
·Updated
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
Affected Software
1 affected component
Diaowen Dwsurvey<=2019-07-22
Event History
Aug 16, 2019
CVE Published
via MITRE·12:28 AM
Data Sourced
via MITRE·12:28 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15095?
CVE-2019-15095 has been classified as a medium severity vulnerability due to its reflected cross-site scripting (XSS) impact.
2
How do I fix CVE-2019-15095?
To mitigate CVE-2019-15095, you should update DWSurvey to a version released after July 22, 2019, which addresses the vulnerability.
3
What type of vulnerability is CVE-2019-15095?
CVE-2019-15095 is a reflected cross-site scripting (XSS) vulnerability that can allow attackers to execute arbitrary scripts in the context of users' browsers.
4
Which versions of DWSurvey are affected by CVE-2019-15095?
DWSurvey versions up to and including 2019-07-22 are affected by CVE-2019-15095.
5
What parameters are involved in CVE-2019-15095?
CVE-2019-15095 involves the 'surveyId' parameter in the design/qu-multi-fillblank!answers.action endpoint.