CVE-2019-16146: XSS
Published Sep 9, 2019
·Updated
Gophish through 0.8.0 allows XSS via a username.
Affected Software
2 affected componentsFixes available
go/github.com/gophish/gophish<0.8.0
0.9.0
Getgophish Gophish<=0.8.0
Remediation
Patch Available
Event History
Sep 9, 2019
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
Description
May 24, 2022
Advisory Published
04:55 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-16146?
CVE-2019-16146 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-16146?
To mitigate CVE-2019-16146, upgrade Gophish to version 0.9.0 or later to eliminate the XSS vulnerability.
3
What software versions are affected by CVE-2019-16146?
CVE-2019-16146 affects all Gophish versions up to and including 0.8.0.
4
Can CVE-2019-16146 be exploited remotely?
Yes, CVE-2019-16146 can be exploited remotely by an attacker to execute XSS attacks via a crafted username.
5
Is user input sanitization a concern in CVE-2019-16146?
Yes, CVE-2019-16146 highlights the lack of proper sanitization for user input, which leads to the XSS vulnerability.