CVE-2019-9142: XSS
Published Feb 25, 2019
·Updated
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
Affected Software
1 affected component
b3log Symphony<3.4.7
Remediation
Patch Available
Event History
Feb 25, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9142?
CVE-2019-9142 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2019-9142?
To fix CVE-2019-9142, upgrade b3log Symphony to version 3.4.7 or later.
3
What are the affected versions of CVE-2019-9142?
CVE-2019-9142 affects b3log Symphony versions prior to 3.4.7.
4
What type of vulnerability is CVE-2019-9142?
CVE-2019-9142 is a cross-site scripting (XSS) vulnerability.
5
Where does CVE-2019-9142 allow XSS injection?
CVE-2019-9142 allows XSS injection via the userIntro and userNickname fields.