Reflected XSS Vulnerability in Micro Focus Solutions Business Manager Application Repository
CVE-2019-18944
4.9MEDIUM
What is CVE-2019-18944?
Micro Focus Solutions Business Manager Application Repository versions before 11.7.1 exhibit a reflected cross-site scripting vulnerability, which could be exploited by attackers to inject malicious scripts into the web application. This could lead to unauthorized actions performed on behalf of the user, compromising the security of sensitive information and potentially enabling further attacks.
Affected Version(s)
Solutions Business Manager < 11.7.1
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Special thanks goes to Alessio Sergi of Verizon Enterprise Solutions for responsibly disclosing this CVE.