CVE-2019-1010199
Dashboard / Vulnerabilities / CVE-2019-1010199
Summary:
Details: ServiceStack ServiceStack Framework 4.5.14 is affected by: Cross Site Scripting (XSS). The impact is: JavaScrpit is reflected in the server response, hence executed by the browser. The component is: the query used in the GET request is prone. The attack vector is: Since there is no server-side validation and If Browser encoding is bypassed, the victim is affected when opening a crafted URL. The fixed version is: 5.2.0.
References: https://github.com/ServiceStack/ServiceStack/commit/a0e0d7de20f5d1712f1793f925496def4383c610
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 04d37ccf026b140d4da64e19d6d3c20f42dcbdd2
Fixed -None
Affected versions
4.5.14
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
