Vulnerability Description
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cnezsoft | Zentao | 11.5.1 |
Related Weaknesses (CWE)
References
- https://github.com/easysoft/zentaopms/issues/35ExploitIssue TrackingThird Party Advisory
- https://github.com/easysoft/zentaopms/issues/35ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2019-14731?
CVE-2019-14731 is a vulnerability with a CVSS score of 5.4 (MEDIUM). An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.
How severe is CVE-2019-14731?
CVE-2019-14731 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14731?
Check the references section above for vendor advisories and patch information. Affected products include: Cnezsoft Zentao.