Vulnerability Description
OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent researcher created the report without any type of validation and that no such vulnerability exists
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Outsystems | Outsystems | >= 10, <= 11 |
Related Weaknesses (CWE)
References
- https://cxsecurity.com/issue/WLB-2019050242ExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2019050242ExploitThird Party Advisory
FAQ
What is CVE-2019-12273?
CVE-2019-12273 is a vulnerability with a CVSS score of 6.5 (MEDIUM). OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsen...
How severe is CVE-2019-12273?
CVE-2019-12273 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12273?
Check the references section above for vendor advisories and patch information. Affected products include: Outsystems Outsystems.