CVE-2019-7417: XSS
XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7417?
The severity of CVE-2019-7417 is medium with a CVSS score of 6.1.
What is the affected software for CVE-2019-7417?
The affected software for CVE-2019-7417 is Ericsson Active Library Explorer version 14.3.
What is the CWE ID for CVE-2019-7417?
The CWE ID for CVE-2019-7417 is CWE-79.
How does CVE-2019-7417 impact the Ericsson Active Library Explorer (ALEX)?
CVE-2019-7417 allows for cross-site scripting (XSS) attacks in multiple parameters of the ALEX servlet in Ericsson Active Library Explorer version 14.3.
Are there any references for CVE-2019-7417?
Yes, you can find more information about CVE-2019-7417 at the following references: [1] http://packetstormsecurity.com/files/151583/Ericsson-Active-Library-Explorer-ALEX-14.3-Cross-Site-Scripting.html [2] http://seclists.org/fulldisclosure/2019/Feb/27 [3] http://www.ericsson.com