A vulnerability has been identified in XHQ (All versions < V6.0.0.2)
Published Dec 12, 2019
9.1
CRITICALCVSS 3.1
EPSS 1.04%
Description
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated, causing the the application to behave in unexpected ways for legitimate users. Successful exploitation does not require for an attacker to be authenticated. A successful attack could allow the import of scripts or generation of malicious links. This could allow the attacker to read or modify contents of the web application. At the time of advisory publication no public exploitation of this security vulnerability was known.
Affected products
-
Affected
- All versions < V6.0.0.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Siemens AG | XHQ | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://cert-portal.siemens.com/productcert/pdf/ssa-525454.pdf x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5201 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-525454.pdf | x_refsource_MISCVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5201 | Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data