Vulnerability Description
Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# onerror='eval(new Buffer(" substring.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gridea | Gridea | 0.8.0 |
Related Weaknesses (CWE)
References
- https://github.com/getgridea/gridea/issues/105ExploitThird Party Advisory
- https://github.com/getgridea/gridea/issues/105ExploitThird Party Advisory
FAQ
What is CVE-2019-12047?
CVE-2019-12047 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# onerror='eval(new Bu...
How severe is CVE-2019-12047?
CVE-2019-12047 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12047?
Check the references section above for vendor advisories and patch information. Affected products include: Gridea Gridea.