Cross-Site Scripting in XAMPP by Apache Friends
CVE-2019-8924

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 May 2019

What is CVE-2019-8924?

The XAMPP software, specifically version 5.6.8, is exposed to a Cross-Site Scripting (XSS) vulnerability through improper handling of user-supplied input in the cds-fpdf.php file. Attackers can exploit this flaw by injecting malicious scripts via the interpret or titel parameters, allowing execution of arbitrary scripts in the context of the user's session. Given that XAMPP is a widely used platform for web development, the risk of exploitation emphasizes the importance of patching or migrating to more secure alternatives, especially as this product is discontinued.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.