Search Results (44597 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-19552 1 Sangoma 1 Freepbx 2024-11-21 4.8 Medium
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator web site, i.e., the/admin/config.php?display=userman URI. An attacker with sufficient privileges can edit the Display Name of a user and embed malicious XSS code. When another user (such as an admin) visits the main User Management screen, the XSS payload will render and execute in the context of the victim user's account.
CVE-2019-19551 1 Sangoma 1 Freepbx 2024-11-21 4.8 Medium
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator web site. An attacker with access to the User Control Panel application can submit malicious values in some of the time/date formatting and time-zone fields. These fields are not being properly sanitized. If this is done and a user (such as an admin) visits the User Management screen and views that user's profile, the XSS payload will render and execute in the context of the victim user's account.
CVE-2019-19547 2 Fedoraproject, Symantec 2 Fedora, Endpoint Detection And Response 2024-11-21 6.1 Medium
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.
CVE-2019-19542 1 Cridio 1 Listingpro 2024-11-21 5.4 Medium
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page.
CVE-2019-19541 1 Cridio 1 Listingpro 2024-11-21 5.4 Medium
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page.
CVE-2019-19540 1 Cridio 1 Listingpro 2024-11-21 6.1 Medium
The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.
CVE-2019-19515 1 Ayision 2 Ays-wr01, Ays-wr01 Firmware 2024-11-21 6.1 Medium
Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings.
CVE-2019-19514 1 Ayision 2 Ays-wr01, Ays-wr01 Firmware 2024-11-21 5.4 Medium
Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID.
CVE-2019-19500 1 Matrix42 1 Workspace Management 2024-11-21 5.4 Medium
Matrix42 Workspace Management 9.1.2.2765 and below allows stored XSS via unfiltered description parameters, as demonstrated by the comment field of a special order for individual software.
CVE-2019-19497 1 Altn 1 Mdaemon Email Server 2024-11-21 5.4 Medium
MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
CVE-2019-19496 1 Alfresco 1 Alfresco 2024-11-21 5.4 Medium
Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document.
CVE-2019-19492 1 Freeswitch 1 Freeswitch 2024-11-21 9.8 Critical
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
CVE-2019-19491 1 Testlink 1 Testlink 2024-11-21 6.1 Medium
TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/tcEdit.php?doAction=doDeleteStep request.
CVE-2019-19466 1 Sceditor 1 Sceditor 2024-11-21 6.1 Medium
SCEditor 2.1.3 allows XSS.
CVE-2019-19461 1 Teampasswordmanager 1 Team Password Manager 2024-11-21 5.4 Medium
Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.
CVE-2019-19457 1 Saltosystem 1 Proaccess Space 2024-11-21 5.4 Medium
SALTO ProAccess SPACE 5.4.3.0 allows XSS.
CVE-2019-19456 1 Wowza 1 Streaming Engine 2024-11-21 6.1 Medium
A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.
CVE-2019-19453 1 Wowza 1 Streaming Engine 2024-11-21 5.4 Medium
Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main page of server settings. This issue was resolved in Wowza Streaming Engine 4.8.5.
CVE-2019-19394 1 Northern.tech 1 Cfengine 2024-11-21 6.1 Medium
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.
CVE-2019-19393 1 Rittal 2 Cmc Pu Iii 7030.000, Cmc Pu Iii 7030.000 Firmware 2024-11-21 6.1 Medium
The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts) as the content is always displayed after and before login. Persistent XSS allows an attacker to modify displayed content or to change the victim's information. Successful exploitation requires access to the web management interface, either with valid credentials or a hijacked session.