CVE-2019-18209: XSS
Published Oct 19, 2019
·Updated
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
Affected Software
1 affected component
Etherpad Etherpad=1.7.5
Remediation
Event History
Oct 19, 2019
CVE Published
via MITRE·12:50 AM
Data Sourced
via MITRE·12:50 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18209?
CVE-2019-18209 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS).
2
How do I fix CVE-2019-18209?
To fix CVE-2019-18209, upgrade Etherpad-Lite to version 1.7.6 or later, which contains patches for this vulnerability.
3
What kind of attack does CVE-2019-18209 allow?
CVE-2019-18209 allows an attacker to execute arbitrary JavaScript code in a user's browser through XSS.
4
Which versions of Etherpad-Lite are affected by CVE-2019-18209?
CVE-2019-18209 affects Etherpad-Lite version 1.7.5 specifically.
5
What are the implications of CVE-2019-18209 for users?
The implications of CVE-2019-18209 for users include potential unauthorized access to user sessions or sensitive data through XSS attacks.