CVE-2019-16684: XSS
Published Sep 30, 2019
·Updated
An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is hovered over in the list or in the Edit page, the payload executes.
Affected Software
1 affected component
Xoops Xoops=2.5.10
Remediation
Patch Available
Event History
Sep 30, 2019
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16684?
The severity of CVE-2019-16684 is medium with a CVSS score of 4.8.
2
How does CVE-2019-16684 affect Xoops 2.5.10?
CVE-2019-16684 affects Xoops 2.5.10 by allowing execution of a JavaScript payload when hovering over an image with that payload as its name in the list or Edit page.
3
How can I fix CVE-2019-16684?
To fix CVE-2019-16684, it is recommended to update to a patched version of Xoops 2.5.10 or apply the necessary security patches.
4
What is the Common Weakness Enumeration (CWE) ID of CVE-2019-16684?
The Common Weakness Enumeration (CWE) ID of CVE-2019-16684 is 79.