Vulnerability Description
Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Afterlogic | Aurora | <= 8.3.9 |
Related Weaknesses (CWE)
References
- https://www.sevenlayers.com/index.php/247-afterlogic-aurora-v8-3-9-build-a3-xss-ExploitThird Party Advisory
- https://www.sevenlayers.com/index.php/247-afterlogic-aurora-v8-3-9-build-a3-xss-ExploitThird Party Advisory
FAQ
What is CVE-2019-16238?
CVE-2019-16238 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login.
How severe is CVE-2019-16238?
CVE-2019-16238 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16238?
Check the references section above for vendor advisories and patch information. Affected products include: Afterlogic Aurora.