CVE-2019-3686: XSS in distri and version parameter in openQA
openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27b was vulnerable to XSS in the distri and version parameter. This was reported through the bug bounty program of Offensive Security
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3686?
CVE-2019-3686 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS).
How do I fix CVE-2019-3686?
To fix CVE-2019-3686, update openQA to a version later than July 22, 2019 or apply necessary security patches provided by the vendor.
What systems are affected by CVE-2019-3686?
CVE-2019-3686 affects openQA versions prior to commit c172e8883d8f32fced5e02f9b6faaacc913df27b released before July 22, 2019.
Is CVE-2019-3686 an active vulnerability?
CVE-2019-3686 should be considered a past vulnerability; however, unpatched systems remain at risk of exploitation.
What are the potential impacts of CVE-2019-3686?
Exploiting CVE-2019-3686 could allow an attacker to execute arbitrary scripts in the context of the user’s browser.