CVE-2019-7671
Summary
| CVE | CVE-2019-7671 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-05 19:29:00 UTC |
| Updated | 2022-10-25 15:39:00 UTC |
| Description | Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Primasystems | Flexair | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Prima Access Control 2.3.35 Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Applied Risk :: Advisories | MISC | applied-risk.com | Third Party Advisory |
| Prima Systems FlexAir | CISA | MISC | www.us-cert.gov | |
| Applied Risk - Applied Risk | MISC | applied-risk.com | Broken Link |
| Prima Systems FlexAir Multiple Vulnerabilities Prima Systems FlexAir Multiple Vulnerabilities - Applied Risk | MISC | applied-risk.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.