Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-16385

Опубликовано: 04 июн. 2020
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a PDF, containing the malicious payload. This results in a reflected XSS payload being executed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cybelesoft:thinfinity_virtualui:*:*:*:*:*:*:*:*
Версия до 2.5.17.2 (включая)

EPSS

Процентиль: 52%
0.00288
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-74

Связанные уязвимости

github
больше 3 лет назад

Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a PDF, containing the malicious payload. This results in a reflected XSS payload being executed.

EPSS

Процентиль: 52%
0.00288
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-74