Unauthenticated Reflected Cross-Site Scripting in Computrols CBAS
CVE-2019-10846

6.1MEDIUM

Key Information:

Vendor

Computrols

Vendor
CVE Published:
23 May 2019

What is CVE-2019-10846?

Computrols CBAS version 18.0.0 is susceptible to unauthenticated reflected cross-site scripting vulnerabilities. This issue arises in the login and password reset pages, where an attacker can exploit the username parameter via GET requests. If successful, this could allow unauthorized users to execute malicious scripts in the context of the victims' browsers, potentially leading to theft of sensitive information such as session cookies or credentials.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.