CVE-2019-7551
Summary
| CVE | CVE-2019-7551 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-10 17:29:00 UTC |
| Updated | 2019-09-27 16:32:00 UTC |
| Description | Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisories Archives - Bishop Fox | MISC | www.bishopfox.com | Third Party Advisory |
| Cantemo Portal Version 3.8.4 - Cross-Site Scripting | MISC | www.bishopfox.com | Exploit, Third Party Advisory |
| Changing the Media Asset Management Paradigm | Cantemo | Cantemo Portal XSS Vulnerabilities | CONFIRM | blog-posts--cantemo.netlify.com | Release Notes, Vendor Advisory |
| Version 4.1.5 — Portal Release Notes 4.1.5 documentation | CONFIRM | doc.cantemo.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.