CVE-2019-4324: XSS
Published Jul 7, 2020
·Updated
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
Affected Software
1 affected component
hcltech Appscan<=10.0.0
Event History
Jul 7, 2020
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4324?
CVE-2019-4324 has been classified with a medium severity due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2019-4324?
To fix CVE-2019-4324, update HCL AppScan Enterprise to version 10.0.1 or later.
3
What types of attacks can CVE-2019-4324 facilitate?
CVE-2019-4324 can facilitate cross-site scripting attacks, which may allow attackers to execute scripts in the context of a user's browser.
4
Which versions of HCL AppScan Enterprise are affected by CVE-2019-4324?
HCL AppScan Enterprise versions up to and including 10.0.0 are affected by CVE-2019-4324.
5
Is there a workaround available for CVE-2019-4324?
There is no official workaround for CVE-2019-4324; upgrading to a patched version is recommended.