ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php ce parameter.
References
Link | Resource |
---|---|
https://github.com/ganglia/ganglia-web/issues/351 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-01-10 19:15
Updated : 2020-01-13 12:05
NVD link : CVE-2019-20378
Mitre link : CVE-2019-20378
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
ganglia
- ganglia-web