Vulnerability Description
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Etherpad | Etherpad | 1.7.5 |
Related Weaknesses (CWE)
References
- https://github.com/ether/etherpad-lite/commit/5879037ddca4ab9a4002adf90fc7ce6c9fPatchThird Party Advisory
- https://github.com/ether/etherpad-lite/commit/5879037ddca4ab9a4002adf90fc7ce6c9fPatchThird Party Advisory
FAQ
What is CVE-2019-18209?
CVE-2019-18209 is a vulnerability with a CVSS score of 6.1 (MEDIUM). templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
How severe is CVE-2019-18209?
CVE-2019-18209 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18209?
Check the references section above for vendor advisories and patch information. Affected products include: Etherpad Etherpad.