CVE-2019-17488: XSS
Published Oct 10, 2019
·Updated
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
Affected Software
1 affected component
b3log Symphony<3.6.0
Event History
Oct 10, 2019
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17488?
CVE-2019-17488 has a medium severity due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-17488?
You can fix CVE-2019-17488 by upgrading b3log Symphony to version 3.6.0 or later.
3
What type of vulnerability is CVE-2019-17488?
CVE-2019-17488 is a cross-site scripting (XSS) vulnerability that affects the HTTP User-Agent header.
4
Which versions of b3log Symphony are affected by CVE-2019-17488?
b3log Symphony versions prior to 3.6.0 are affected by CVE-2019-17488.
5
Who is the vendor associated with CVE-2019-17488?
The vendor associated with CVE-2019-17488 is b3log, the developer of Symphony.