Vulnerability Description
Premium Software CLEditor 1.4.5 and earlier is affected by: Cross Site Scripting (XSS). The impact is: An attacker might be able to inject arbitrary html and script code into the web site. The component is: jQuery plug-in. The attack vector is: the victim must open a crafted href attribute of a link (A) element.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Premiumsoftware | Cleditor | <= 1.4.5 |
Related Weaknesses (CWE)
References
- https://drive.google.com/drive/folders/1UxgdL8SJO6KKnG3bh0-LTl7C6i41VwoW?usp=shaExploitThird Party Advisory
- https://drive.google.com/drive/folders/1UxgdL8SJO6KKnG3bh0-LTl7C6i41VwoW?usp=shaExploitThird Party Advisory
FAQ
What is CVE-2019-1010113?
CVE-2019-1010113 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Premium Software CLEditor 1.4.5 and earlier is affected by: Cross Site Scripting (XSS). The impact is: An attacker might be able to inject arbitrary html and script code into the web site. The compone...
How severe is CVE-2019-1010113?
CVE-2019-1010113 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1010113?
Check the references section above for vendor advisories and patch information. Affected products include: Premiumsoftware Cleditor.