First published: Mon Sep 30 2019(Updated: )
A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send back a victim's cleartext credentials to an attacker via a login/?reason=failure&NTLM= URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GFI Software KerioControl | =9.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16414 is classified as a medium severity vulnerability due to its potential for exploitation via a DOM-based XSS attack.
To fix CVE-2019-16414, update GFI Kerio Control to the latest version that addresses this XSS vulnerability.
CVE-2019-16414 facilitates a DOM-based cross-site scripting (XSS) attack, which can exploit the login page to capture credentials.
GFI Kerio Control version 9.3.0 is specifically affected by CVE-2019-16414.
Yes, CVE-2019-16414 can result in credential theft by sending the victim's cleartext login information to an attacker.