Vulnerability Description
Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also applies to the search functionality for the searchKey parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zucchetti | Infobusiness | <= 4.4.1 |
Related Weaknesses (CWE)
References
- https://blog.hacktivesecurity.com/index.php?controller=post&action=view&id_post=ExploitThird Party Advisory
- https://blog.hacktivesecurity.com/index.php?controller=post&action=view&id_post=ExploitThird Party Advisory
FAQ
What is CVE-2019-18205?
CVE-2019-18205 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64...
How severe is CVE-2019-18205?
CVE-2019-18205 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18205?
Check the references section above for vendor advisories and patch information. Affected products include: Zucchetti Infobusiness.