TemaTres 3.0 has reflected XSS via the replace_string or search_string parameter to the vocab/admin.php?doAdmin=bulkReplace URI.
References
Link | Resource |
---|---|
https://medium.com/@Pablo0xSantiago/cve-2019-14344-tematres-3-0-cross-site-scripting-reflected-xss-3826a23c7fff | Exploit Third Party Advisory |
https://github.com/tematres/TemaTres-Vocabulary-Server/commits/master | Patch |
Configurations
Information
Published : 2019-12-13 08:15
Updated : 2019-12-17 12:38
NVD link : CVE-2019-14344
Mitre link : CVE-2019-14344
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
vocabularyserver
- tematres