4.3
CVSSv2

CVE-2019-11454

Published: 22/04/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit prior to 5.25.3 allows a remote unauthenticated malicious user to introduce arbitrary JavaScript via manipulation of an unsanitized user field of the Authorization header for HTTP Basic Authentication, which is mishandled during an _viewlog operation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mmonit monit

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 18.10

canonical ubuntu linux 19.04

fedoraproject fedora 31

fedoraproject fedora 32

Vendor Advisories

Debian Bug report logs - #927775 monit: CVE-2019-11454 CVE-2019-11455 Package: src:monit; Maintainer for src:monit is Sergey B Kirpichev <skirpichev@gmailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 23 Apr 2019 04:57:01 UTC Severity: serious Tags: security, upstream Found in versions monit ...
Several security issues were fixed in Monit ...