Vulnerability Description
Blinger.io v.1.0.2519 is vulnerable to Blind/Persistent XSS. An attacker can send arbitrary JavaScript code via a built-in communication channel, such as Telegram, WhatsApp, Viber, Skype, Facebook, Vkontakte, or Odnoklassniki. This is mishandled within the administration panel for conversations/all, conversations/inbox, conversations/unassigned, and conversations/closed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blinger | Blinger | 1.0.2519 |
Related Weaknesses (CWE)
References
- https://blinger.io/Vendor Advisory
- https://github.com/Security-AVS/CVE-2019-13633ExploitThird Party Advisory
- https://blinger.io/Vendor Advisory
- https://github.com/Security-AVS/CVE-2019-13633ExploitThird Party Advisory
FAQ
What is CVE-2019-13633?
CVE-2019-13633 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Blinger.io v.1.0.2519 is vulnerable to Blind/Persistent XSS. An attacker can send arbitrary JavaScript code via a built-in communication channel, such as Telegram, WhatsApp, Viber, Skype, Facebook, Vk...
How severe is CVE-2019-13633?
CVE-2019-13633 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13633?
Check the references section above for vendor advisories and patch information. Affected products include: Blinger Blinger.