Home CVE Database CVE-2019-9957

CVE-2019-9957

Description

Stored XSS within Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The XSS payload is stored by creating a new user account, and setting the username to an XSS payload. The stored payload can then be triggered by accessing the \"Set Security Levels\" or \"View User/Group Relationships\" page. If the attacker does not currently have permission to create a new user, another vulnerability such as CSRF must be exploited first.

Priority: LOW
CVSS v3: 5.4
Publish Date: Jun 24, 2019
Related ID: --
CVSS v2: MEDIUM
Modified Date: Jun 27, 2019

Find out more about CVE-2019-9957 from the MITRE-CVE dictionary and NIST NVD


Products Affected

Login may be required to access defects or downloads.

Product Name Status Defect Fixed Downloads
Linux
Wind River Linux LTS 17 Not Vulnerable -- -- --
Wind River Linux 9 Not Vulnerable -- -- --
Wind River Linux 8 Not Vulnerable -- -- --
Wind River Linux 7 Not Vulnerable -- -- --
Wind River Linux LTS 18 Not Vulnerable -- -- --
VxWorks
VxWorks 7 Not Vulnerable -- -- --
VxWorks 6.9 Not Vulnerable -- -- --
VxWorks 6.8 Not Vulnerable -- -- --
VxWorks 6.7 Not Vulnerable -- -- --
VxWorks 6.6 Not Vulnerable -- -- --
VxWorks 6.4 Not Vulnerable -- -- --
VxWorks 5.5 Not Vulnerable -- -- --

Related Products

Product name Status
Linux
Linux 7 SCP Not Vulnerable
Linux 7 CGP Not Vulnerable

Comments

It doesn\'t impact WRLinux

Live chat
Online