CVE-2019-13189 Information

Description

In Knowage through 6.1.1 there is XSS via the start_url or user_id field to the ChangePwdServlet page.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://blog.contentsecurity.com.au/security-advisory-knowage-cross-site-scripting In Knowage through 6.1.1 there is XSS via the start_url or user_id field to the ChangePwdServlet page.

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: