PoC Index

CVE-2018-19509

MEDIUM 6.1EPSS 1.1%

wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encoding. Because it is possible to insert arbitrary strings into the database, any JavaScript could be executed by the administrator, leading to XSS.

CVSS v3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.06% chance of exploitation in the next 30 days, 62th percentile
Published
2019-03-17
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related