Cross Site Scripting Vulnerability in ServiceStack Framework by ServiceStack
CVE-2019-1010199
What is CVE-2019-1010199?
The ServiceStack Framework version 4.5.14 is susceptible to a Cross Site Scripting (XSS) vulnerability due to a flaw in how it handles user input in GET requests. When a crafted URL is accessed, the framework fails to perform adequate server-side validation, allowing malicious JavaScript to be reflected in the server's response and executed in the user's browser. This vulnerability poses a risk as it enables attackers to exploit unsuspecting users by executing arbitrary scripts in their sessions. Users are strongly advised to upgrade to version 5.2.0 or later to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ServiceStack Framework 4.5.14 [fixed: 5.2.0]
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
