{"api_version":"1","generated_at":"2026-07-23T09:41:01+00:00","cve":"CVE-2019-6031","urls":{"html":"https://cve.report/CVE-2019-6031","api":"https://cve.report/api/cve/CVE-2019-6031.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-6031","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-6031"},"summary":{"title":"CVE-2019-6031","description":"Cross-site scripting vulnerability in KINZA for Windows version 5.9.2 and earlier and for Mac version 5.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via RSS reader.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2019-12-26 16:15:00","updated_at":"2020-01-06 15:00:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://jvn.jp/en/jp/JVN63047298/index.html","name":"http://jvn.jp/en/jp/JVN63047298/index.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"JVN#63047298: Kinza vulnerable to cross-site scripting","mime":"text/xml","httpstatus":"200","archivestatus":"0"},{"url":"https://www.kinza.jp/download/releases/","name":"https://www.kinza.jp/download/releases/","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"機能追加など各種更新履歴 | ウェブブラウザ:Kinza - 国産で軽い・使いやすい","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-6031","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-6031","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"6031","vulnerable":"1","versionEndIncluding":"5.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dayz","cpe5":"kinza","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"macos","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6031","vulnerable":"1","versionEndIncluding":"5.9.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dayz","cpe5":"kinza","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-6031","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Dayz Inc.","product":{"product_data":[{"product_name":"KINZA","version":{"version_data":[{"version_value":"for Windows version 5.9.2 and earlier and for Mac version 5.0.0 and earlier"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Cross-site scripting"}]}]},"references":{"reference_data":[{"url":"https://www.kinza.jp/download/releases/","refsource":"MISC","name":"https://www.kinza.jp/download/releases/"},{"url":"http://jvn.jp/en/jp/JVN63047298/index.html","refsource":"MISC","name":"http://jvn.jp/en/jp/JVN63047298/index.html"}]},"description":{"description_data":[{"lang":"eng","value":"Cross-site scripting vulnerability in KINZA for Windows version 5.9.2 and earlier and for Mac version 5.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via RSS reader."}]}},"nvd":{"publishedDate":"2019-12-26 16:15:00","lastModifiedDate":"2020-01-06 15:00:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:dayz:kinza:*:*:*:*:*:macos:*:*","versionEndIncluding":"5.0.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:dayz:kinza:*:*:*:*:*:windows:*:*","versionEndIncluding":"5.9.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"6031","Ordinal":"143685","Title":"CVE-2019-6031","CVE":"CVE-2019-6031","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"6031","Ordinal":"1","NoteData":"Cross-site scripting vulnerability in KINZA for Windows version 5.9.2 and earlier and for Mac version 5.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via RSS reader.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"6031","Ordinal":"2","NoteData":"2019-12-26","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"6031","Ordinal":"3","NoteData":"2019-12-26","Type":"Other","Title":"Modified"}]}}}