CVE-2019-7250
Summary
| CVE | CVE-2019-7250 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-31 09:29:00 UTC |
| Updated | 2019-02-01 01:00:00 UTC |
| Description | An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configuration panel may allow a malicious user to use both label text and references text to inject arbitrary JavaScript code (via SCRIPT elements, event handlers, etc.). Since this code is stored by the plugin, the attacker may be able to target anyone who opens the configuration panel of the plugin. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cross Reference Project | Cross Reference | 36 | All | All | All |
| Application | Cross Reference Project | Cross Reference | 36 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Stored XSS vulnerability in preview boxes via label and references text · Issue #32 · davidrthorn/cross_reference · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.