CVE-2019-17496: XSS
Published Oct 10, 2019
·Updated
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
Affected Software
2 affected componentsFixes available
composer/craftcms/cms<3.3.8
3.3.8
Craft CMS<3.3.8
Remediation
Event History
Oct 10, 2019
CVE Published
via MITRE·11:32 PM
Data Sourced
via MITRE·11:32 PM
Description
May 24, 2022
Advisory Published
04:58 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-17496?
The severity of CVE-2019-17496 is medium with a CVSS score of 6.1.
2
How does CVE-2019-17496 affect Craft CMS?
CVE-2019-17496 affects Craft CMS versions before 3.3.8.
3
What is the vulnerability in CVE-2019-17496?
The vulnerability in CVE-2019-17496 is a stored XSS vulnerability.
4
How can the stored XSS vulnerability in CVE-2019-17496 be exploited?
The stored XSS vulnerability in CVE-2019-17496 can be exploited by injecting malicious code into the name field, which is mishandled during site deletion.
5
How can CVE-2019-17496 be fixed?
CVE-2019-17496 can be fixed by updating Craft CMS to version 3.3.8 or later.