VulnerabilityModified
CVE-2019-14731
There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.
MEDIUM 5.4EPSS 0.59%
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cnezsoft/zentao
- Source
- cve@mitre.org
References
- https://github.com/easysoft/zentaopms/issues/35Exploit, Issue Tracking, Third Party Advisory
- https://github.com/easysoft/zentaopms/issues/35Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.