First published: Fri Feb 26 2021(Updated: )
Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.
Credit: security@microfocus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus Solutions Business Manager | <11.7.1 |
Upgrade SBM to 11.7.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18942 has a high severity rating due to its potential for stored cross-site scripting (XSS) attacks.
To fix CVE-2019-18942, upgrade Micro Focus Solutions Business Manager to version 11.7.1 or later.
CVE-2019-18942 allows attackers to execute arbitrary scripts in the context of users who view the affected application.
All versions of Micro Focus Solutions Business Manager prior to 11.7.1 are affected by CVE-2019-18942.
Exploitation of CVE-2019-18942 does not require authentication, making it particularly dangerous.