CVE-2019-25028: Stored cross-site scripting in Grid component in Vaadin 7 and 8
Published Apr 23, 2021
·Updated
Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 through 8.8.4 (Vaadin 8.0.0 through 8.8.4) allows attacker to inject malicious JavaScript via unspecified vector
Affected Software
2 affected components
Vaadin Vaadin>=7.4.0<7.7.20
Vaadin Vaadin>=8.0.0<8.8.5
Remediation
Patch Available
Patch Available
Event History
Apr 23, 2021
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-25028?
CVE-2019-25028 has been classified with a high severity due to the risk of JavaScript injection attacks.
2
How do I fix CVE-2019-25028?
To fix CVE-2019-25028, upgrade to Vaadin versions 7.7.20 or later, or 8.8.5 or later.
3
What versions of Vaadin are affected by CVE-2019-25028?
CVE-2019-25028 affects Vaadin versions 7.4.0 through 7.7.19 and 8.0.0 through 8.8.4.
4
What type of vulnerability is CVE-2019-25028?
CVE-2019-25028 is a vulnerability related to missing variable sanitization, allowing JavaScript injection.
5
Can CVE-2019-25028 lead to data breaches?
Yes, CVE-2019-25028 can potentially lead to data breaches by allowing attackers to execute malicious scripts.