ZeroHour

CVE-2019-19912

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p55
Published
()
Modified
Description

In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file.

Vendors
intland
Products
codebeamer
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.