Vulnerability Description
index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ovidentia | Ovidentia | 8.4.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/153737/Ovidentia-8.4.3-Cross-Site-Scripting
- https://github.com/Kitsun3Sec/exploits/blob/master/cms/ovidentia/exploitXSSOvideExploitThird Party Advisory
- http://packetstormsecurity.com/files/153737/Ovidentia-8.4.3-Cross-Site-Scripting
- https://github.com/Kitsun3Sec/exploits/blob/master/cms/ovidentia/exploitXSSOvideExploitThird Party Advisory
FAQ
What is CVE-2019-13977?
CVE-2019-13977 is a vulnerability with a CVSS score of 5.4 (MEDIUM). index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=...
How severe is CVE-2019-13977?
CVE-2019-13977 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13977?
Check the references section above for vendor advisories and patch information. Affected products include: Ovidentia Ovidentia.