CVE-2019-7677: XSS
Published Feb 9, 2019
·Updated
XSS exists in Enphase Envoy R3.. via the profileName parameter to the /home URI on TCP port 8888.
Affected Software
1 affected component
Enphase Envoy>=3.0.0<=3.9.0
Event History
Feb 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-7677?
CVE-2019-7677 is classified as a moderate severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2019-7677?
To mitigate CVE-2019-7677, ensure that your Enphase Envoy software is updated to a version beyond 3.9.0.
3
What are the effects of exploiting CVE-2019-7677?
Exploitation of CVE-2019-7677 can lead to unauthorized access to user information through a malicious script.
4
Which versions of Enphase Envoy are affected by CVE-2019-7677?
CVE-2019-7677 affects Enphase Envoy versions from 3.0.0 to 3.9.0.
5
How does CVE-2019-7677 occur?
CVE-2019-7677 occurs via an improper handling of the profileName parameter in the /home URI on TCP port 8888.