Vulnerability Description
LayerBB 1.1.3 allows XSS via the application/commands/new.php pm_title variable, a related issue to CVE-2019-17997.
CVSS Score
6.1
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Layerbb | Layerbb | 1.1.3 |
Related Weaknesses (CWE)
References
- http://blog.topsec.com.cn/%E5%A4%A9%E8%9E%8D%E4%BF%A1%E5%85%B3%E4%BA%8Elayerbb-1ExploitThird Party Advisory
- http://blog.topsec.com.cn/%E5%A4%A9%E8%9E%8D%E4%BF%A1%E5%85%B3%E4%BA%8Elayerbb-1ExploitThird Party Advisory
FAQ
What is CVE-2019-13972?
CVE-2019-13972 is a vulnerability with a CVSS score of 6.1 (MEDIUM). LayerBB 1.1.3 allows XSS via the application/commands/new.php pm_title variable, a related issue to CVE-2019-17997.
How severe is CVE-2019-13972?
CVE-2019-13972 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13972?
Check the references section above for vendor advisories and patch information. Affected products include: Layerbb Layerbb.