CVE-2019-18654: XSS
Published Nov 1, 2019
·Updated
A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.
Affected Software
2 affected components
AVG Anti-Virus=19.3.3084
Microsoft Windows
Event History
Nov 1, 2019
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
Description
Frequently Asked Questions
1
What is CVE-2019-18654?
CVE-2019-18654 is a Cross Site Scripting (XSS) issue in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440.
2
How does CVE-2019-18654 affect AVG AntiVirus?
CVE-2019-18654 allows an attacker to execute JavaScript code via an SSID Name in the Network Notification Popup.
3
What is the severity of CVE-2019-18654?
CVE-2019-18654 has a severity rating of 6.1 (Medium).
4
How can I fix CVE-2019-18654?
To fix CVE-2019-18654, update AVG AntiVirus (Internet Security Edition) to version 19.3.4241.440 or later.
5
Is Microsoft Windows vulnerable to CVE-2019-18654?
No, Microsoft Windows is not vulnerable to CVE-2019-18654.