CVE-2019-16414: XSS
A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send back a victim's cleartext credentials to an attacker via a login/?reason=failure&NTLM= URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16414?
CVE-2019-16414 is classified as a medium severity vulnerability due to its potential for exploitation via a DOM-based XSS attack.
How do I fix CVE-2019-16414?
To fix CVE-2019-16414, update GFI Kerio Control to the latest version that addresses this XSS vulnerability.
What type of attack does CVE-2019-16414 facilitate?
CVE-2019-16414 facilitates a DOM-based cross-site scripting (XSS) attack, which can exploit the login page to capture credentials.
Which version of GFI Kerio Control is affected by CVE-2019-16414?
GFI Kerio Control version 9.3.0 is specifically affected by CVE-2019-16414.
Can CVE-2019-16414 lead to credential theft?
Yes, CVE-2019-16414 can result in credential theft by sending the victim's cleartext login information to an attacker.