CVE-2019-6180: XSS
A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which may then be executed in the user's web browser. The JavaScript code is not executed on LXCA itself.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-6180.
What is the severity level of CVE-2019-6180?
The severity level of CVE-2019-6180 is medium (4.8).
What is the affected software for CVE-2019-6180?
The affected software for CVE-2019-6180 is Lenovo XClarity Administrator versions prior to 2.5.0.
How does CVE-2019-6180 work?
CVE-2019-6180 is a stored cross-site scripting (XSS) vulnerability that allows an administrative user to store JavaScript code in Lenovo XClarity Administrator, which can be executed in the user's web browser.
Is there a fix available for CVE-2019-6180?
Yes, a fix for CVE-2019-6180 is available. Please refer to the official Lenovo support page for more information.