CVE-2019-16321: XSS
Published Sep 15, 2019
·Updated
ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATHINFO.
Affected Software
2 affected components
ScadaBR ScadaBR=1.0ce
ScadaBR ScadaBR=1.1.0-rc
Event History
Sep 15, 2019
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16321?
CVE-2019-16321 has a moderate severity level due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2019-16321?
To fix CVE-2019-16321, update to a patched version of ScadaBR beyond 1.1.0-RC or implement input validation controls.
3
What type of vulnerability is CVE-2019-16321?
CVE-2019-16321 is classified as a cross-site scripting (XSS) vulnerability.
4
Which versions of ScadaBR are affected by CVE-2019-16321?
CVE-2019-16321 affects ScadaBR versions 1.0CE and 1.1.0-RC.
5
Can CVE-2019-16321 be exploited remotely?
Yes, CVE-2019-16321 can be exploited remotely by an attacker targeting specific URL requests.