First published: Wed May 08 2019(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit feature; (3) content parameter in the profile feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Htmly | =2.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8349 is a vulnerability that allows remote attackers to inject arbitrary web scripts or HTML in HTMLy version 2.7.4.
The severity of CVE-2019-8349 is medium with a CVSS score of 6.1.
Remote attackers can exploit CVE-2019-8349 by injecting arbitrary web script or HTML via the destination and content parameters in certain features of HTMLy version 2.7.4.
The CVE system is a dictionary of publicly known information security vulnerabilities and exposures that are assigned unique identifiers.
To mitigate CVE-2019-8349, it is recommended to update to a newer version of HTMLy that does not have the XSS vulnerabilities or apply patches provided by the vendor.