CVE-2019-18356: XSS
Published Oct 23, 2019
·Updated
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2).
Affected Software
1 affected component
Thycotic Secret Server<10.7.000000
Event History
Oct 23, 2019
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18356?
CVE-2019-18356 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-18356?
To fix CVE-2019-18356, upgrade Thycotic Secret Server to version 10.7 or later.
3
What systems are affected by CVE-2019-18356?
CVE-2019-18356 affects Thycotic Secret Server versions prior to 10.7.
4
What kind of vulnerability is CVE-2019-18356?
CVE-2019-18356 is an XSS vulnerability that allows attackers to inject malicious scripts into web pages viewed by users.
5
Is there a workaround for CVE-2019-18356?
There is no official workaround for CVE-2019-18356 other than upgrading to the patched version.