3.5
CVSSv2

CVE-2019-14804

Published: 09/08/2019 Updated: 14/08/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

una una 10.0.0

Exploits

# Exploit Title: [UNA - 1000-RC1 stored XSS vuln] # Date: [2019 08 10] # Exploit Author: [GregPriest] # Vendor Homepage: [unaio/] # Software Link: [githubcom/unaio/una/tree/master/studio] # Version: [UNA - 1000-RC1] # Tested on: [Windows/Linux ] # CVE : [CVE-2019-14804] UNA-v1000-RC1 [Stored XSS Vulnerability]#1 Sign i ...
UNA version 1000 RC1 suffers from a persistent cross site scripting vulnerability in polyglotphp ...