Vulnerability Description
OPT/NET BV NG-NetMS version v3.6-2 and earlier versions contains a Cross Site Scripting (XSS) vulnerability in /js/libs/jstree/demo/filebrowser/index.php page. The "id" and "operation" GET parameters can be used to inject arbitrary JavaScript which is returned in the page's response that can result in Cross-site scripting.This attack appear to be exploitable via network connectivity.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opt-Net | Ng-Netms | <= 3.6-2 |
Related Weaknesses (CWE)
References
- https://inf0seq.github.io/cve/2019/01/20/Cross-site-scripting-%28XSS%29-in-OPTOS
- https://sourceforge.net/projects/ngnms/ProductThird Party Advisory
- https://www.owasp.org/index.php/Cross-site_Scripting_%28XSS%29
- https://inf0seq.github.io/cve/2019/01/20/Cross-site-scripting-%28XSS%29-in-OPTOS
- https://sourceforge.net/projects/ngnms/ProductThird Party Advisory
- https://www.owasp.org/index.php/Cross-site_Scripting_%28XSS%29
FAQ
What is CVE-2019-1000024?
CVE-2019-1000024 is a vulnerability with a CVSS score of 6.1 (MEDIUM). OPT/NET BV NG-NetMS version v3.6-2 and earlier versions contains a Cross Site Scripting (XSS) vulnerability in /js/libs/jstree/demo/filebrowser/index.php page. The "id" and "operation" GET parameters ...
How severe is CVE-2019-1000024?
CVE-2019-1000024 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1000024?
Check the references section above for vendor advisories and patch information. Affected products include: Opt-Net Ng-Netms.