CVE-2019-19496: XSS
Published Dec 2, 2019
·Updated
Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document.
Affected Software
1 affected component
Alfresco Alfresco<5.2.5
Event History
Dec 2, 2019
CVE Published
via MITRE·03:01 AM
Data Sourced
via MITRE·03:01 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19496?
The severity of CVE-2019-19496 is medium with a CVSS score of 5.4.
2
How does CVE-2019-19496 affect Alfresco Enterprise?
CVE-2019-19496 affects Alfresco Enterprise versions up to and excluding 5.2.5.
3
What is the vulnerability description of CVE-2019-19496?
CVE-2019-19496 is a stored cross-site scripting (XSS) vulnerability in Alfresco Enterprise that occurs when an uploaded HTML document is not properly sanitized.
4
How can I exploit CVE-2019-19496?
To exploit CVE-2019-19496, an attacker can upload a malicious HTML document containing script code, which will then be executed by unsuspecting users who view the document.
5
How can I mitigate CVE-2019-19496?
To mitigate CVE-2019-19496, upgrade Alfresco Enterprise to version 5.2.5 or later, which includes a fix for this vulnerability.