Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-13932

Опубликовано: 12 дек. 2019
Источник: nvd
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated, causing the the application to behave in unexpected ways for legitimate users. Successful exploitation does not require for an attacker to be authenticated. A successful attack could allow the import of scripts or generation of malicious links. This could allow the attacker to read or modify contents of the web application. At the time of advisory publication no public exploitation of this security vulnerability was known.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:siemens:xhq:*:*:*:*:*:*:*:*
Версия до 6.0.0.2 (исключая)

EPSS

Процентиль: 58%
0.00369
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

github
больше 3 лет назад

A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated, causing the the application to behave in unexpected ways for legitimate users. Successful exploitation does not require for an attacker to be authenticated. A successful attack could allow the import of scripts or generation of malicious links. This could allow the attacker to read or modify contents of the web application. At the time of advisory publication no public exploitation of this security vulnerability was known.

EPSS

Процентиль: 58%
0.00369
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-20
CWE-20