CVE-2019-7671 Information
Feb 14, 2021
cve
Description
Prima Systems FlexAir Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
http://packetstormsecurity.com/files/155274/Prima-Access-Control-2.3.35-Cross-Site-Scripting.html https://applied-risk.com/index.php/download_file/view/199/165 https://applied-risk.com/labs/advisories https://applied-risk.com/resources/ar-2019-007 https://www.us-cert.gov/ics/advisories/icsa-19-211-02
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: