CVE-2019-11643

Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to the applicable data store. This can be exploited remotely by both authenticated and unauthenticated users.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:oneshield:oneshield_policy:*:*:*:*:*:*:*:*

Information

Published : 2019-05-08 09:29

Updated : 2019-05-08 13:15


NVD link : CVE-2019-11643

Mitre link : CVE-2019-11643


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

oneshield

  • oneshield_policy