CVE-2019-18205

Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also applies to the search functionality for the searchKey parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zucchetti:infobusiness:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:32

Type Values Removed Values Added
References () https://blog.hacktivesecurity.com/index.php?controller=post&action=view&id_post=42 - Exploit, Third Party Advisory () https://blog.hacktivesecurity.com/index.php?controller=post&action=view&id_post=42 - Exploit, Third Party Advisory

Information

Published : 2019-10-30 19:15

Updated : 2024-11-21 04:32


NVD link : CVE-2019-18205

Mitre link : CVE-2019-18205

CVE.ORG link : CVE-2019-18205


JSON object : View

Products Affected

zucchetti

  • infobusiness
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')