https://seclists.org/oss-sec/2025/q4/142: [CVE-2019-18860] SQUID-2023:6 Cross Site Scripting in cachemgr.cgi
Published Nov 5, 2025
·Updated
Affected Software
1 affected component
Squid Proxy Cache
Frequently Asked Questions
1
What is the severity of CVE-2019-18860?
CVE-2019-18860 is classified as a medium severity Cross Site Scripting vulnerability in Squid Proxy Cache.
2
How do I fix CVE-2019-18860?
To fix CVE-2019-18860, update your Squid Proxy Cache to the latest version where the vulnerability is patched.
3
What are the consequences of exploiting CVE-2019-18860?
Exploiting CVE-2019-18860 could allow an attacker to execute arbitrary code in the context of the user’s browser.
4
Which version of Squid Proxy Cache is affected by CVE-2019-18860?
CVE-2019-18860 affects specific versions of Squid Proxy Cache that allow Cross Site Scripting through cachemgr.cgi.
5
Is there a workaround for CVE-2019-18860 if immediate patching is not possible?
A temporary workaround for CVE-2019-18860 is to restrict access to cachemgr.cgi to trusted IP addresses until the software is updated.