CVE-2019-18793: XSS
Published Nov 13, 2019
·Updated
Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.
Affected Software
1 affected component
Parallels Parallels Plesk Panel=9.5
Event History
Nov 13, 2019
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18793?
CVE-2019-18793 is classified as a medium-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-18793?
To fix CVE-2019-18793, update Parallels Plesk Panel to the latest version that addresses this XSS vulnerability.
3
What impact does CVE-2019-18793 have on users?
CVE-2019-18793 allows attackers to execute arbitrary JavaScript in the context of a user's session, potentially compromising user data and session integrity.
4
Which versions of Parallels Plesk Panel are affected by CVE-2019-18793?
CVE-2019-18793 specifically affects Parallels Plesk Panel version 9.5.
5
Is mitigation available for CVE-2019-18793?
While updating to a patched version is the best solution, users can also implement input validation to mitigate the effects of CVE-2019-18793.