CVE-2019-9554: XSS
Published Dec 31, 2019
·Updated
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
Affected Software
1 affected component
Craft CMS=3.1.12
Event History
Dec 31, 2019
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
Description
Frequently Asked Questions
1
What is CVE-2019-9554?
CVE-2019-9554 is a vulnerability in the Craft CMS software version 3.1.12 Pro that allows for cross-site scripting (XSS) attacks.
2
What is the severity of CVE-2019-9554?
CVE-2019-9554 has a severity level of medium, with a CVSS score of 6.1.
3
How does CVE-2019-9554 impact Craft CMS?
CVE-2019-9554 allows an attacker to insert malicious code into the header insertion field in Craft CMS, leading to potential XSS attacks.
4
What is the affected software version of CVE-2019-9554?
The affected software version of CVE-2019-9554 is Craft CMS 3.1.12 Pro.
5
How can I mitigate the risk of CVE-2019-9554?
To mitigate the risk of CVE-2019-9554, it is recommended to update Craft CMS to a version beyond 3.1.12 Pro, where the vulnerability is patched.