PoC Index

CVE-2019-19912

MEDIUM 4.8EPSS 0.8%

In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file.

CVSS v3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
0.80% chance of exploitation in the next 30 days, 54th percentile
Published
2020-03-30
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related