CVE-2019-18649

When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:untangle:ng_firewall:14.2.0:*:*:*:*:*:*:*

Information

Published : 2019-11-14 07:15

Updated : 2019-11-14 12:23


NVD link : CVE-2019-18649

Mitre link : CVE-2019-18649


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

untangle

  • ng_firewall