Vulnerability Description
An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBED element.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thinksaas | Thinksaas | 2.91 |
Related Weaknesses (CWE)
References
- https://github.com/thinksaas/ThinkSAAS/issues/21ExploitIssue TrackingThird Party Advisory
- https://github.com/thinksaas/ThinkSAAS/issues/21ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2019-16665?
CVE-2019-16665 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBED...
How severe is CVE-2019-16665?
CVE-2019-16665 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16665?
Check the references section above for vendor advisories and patch information. Affected products include: Thinksaas Thinksaas.