CVE Feed

    Dashboard / CVE / CVE-2019-7250

    CVE-2019-7250

    An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configuration panel may allow a malicious user to use both label text and references text to inject arbitrary JavaScript code (via SCRIPT elements, event handlers, etc.). Since this code is stored by the plugin, the attacker may be able to target anyone who opens the configuration panel of the plugin.

    Published:Jan 31, 2019
    Last Modified:Nov 21, 2024
    EPS:Jan 31, 2019
    EPSS Score:0.0024
    CVSS Score:6.1

    Affected Products

    Vendor
    Cross Reference Project
    Product
    Cross Reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High