CVE-2019-18265
Summary
| CVE | CVE-2019-18265 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-30 23:15:00 UTC |
| Updated | 2022-12-09 00:44:00 UTC |
| Description | Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Digitalalertsystems | Dasdec I | - | All | All | All |
| Hardware | Digitalalertsystems | Dasdec Ii | - | All | All | All |
| Hardware | Digitalalertsystems | Dasdec Iii | - | All | All | All |
| Operating System | Digitalalertsystems | Dasdec Iii Firmware | All | All | All | All |
| Operating System | Digitalalertsystems | Dasdec Ii Firmware | All | All | All | All |
| Operating System | Digitalalertsystems | Dasdec I Firmware | All | All | All | All |
| Hardware | Digitalalertsystems | One-net | - | All | All | All |
| Operating System | Digitalalertsystems | One-net Firmware | All | All | All | All |
| Hardware | Digitalalertsystems | One-net Se | - | All | All | All |
| Operating System | Digitalalertsystems | One-net Se Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory | DAS 2022 | MISC | www.digitalalertsystems.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.