CRITICAL
Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS
Published Apr 10, 2019
9.0
CRITICALCVSS 3.1
EPSS 1.73%
Description
Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://blog-posts--cantemo.netlify.com/news/2019/03/cantemo-portal-xss-vulnerabilities/ x_refsource_CONFIRMRelease NotesVendor Advisory
- https://doc.cantemo.com/latest/ReleaseNotes/intro.html#version-3-4-9 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.bishopfox.com/blog/news-category/advisories/ x_refsource_MISCThird Party Advisory
- https://www.bishopfox.com/news/2019/03/cantemo-portal-version-3-8-4-cross-site-scripting/ x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://blog-posts--cantemo.netlify.com/news/2019/03/cantemo-portal-xss-vulnerabilities/ | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://doc.cantemo.com/latest/ReleaseNotes/intro.html#version-3-4-9 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.bishopfox.com/blog/news-category/advisories/ | x_refsource_MISCThird Party Advisory | |
| https://www.bishopfox.com/news/2019/03/cantemo-portal-version-3-8-4-cross-site-scripting/ | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 10, 2019
Updated Aug 4, 2024
Reserved Feb 6, 2019
Link CVE-2019-7551
CISA Vulnrichment
Updated n/a