CVE-2019-19912: XSS
In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19912?
The severity of CVE-2019-19912 is considered medium due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2019-19912?
To fix CVE-2019-19912, update Intland codeBeamer ALM to version 9.6 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2019-19912?
CVE-2019-19912 is classified as a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2019-19912?
Authenticated users of Intland codeBeamer ALM versions 9.5 and earlier are affected by CVE-2019-19912.
What can attackers do with CVE-2019-19912?
Attackers can inject arbitrary scripts into the application through the Upload Flash File feature in CVE-2019-19912.