383
VMScore

CVE-2019-15233

Published: 20/08/2019 Updated: 07/04/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Live:Text Box macro in the Old Street Live Input Macros app prior to 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oldstreetsolutions live input macros

Github Repositories

(FAB-2019-00157) Vulnerability discoverd by me CVE-2019-15233

CVE-2019-15233 (FAB-2019-00157) Vulnerability discoverd by me CVE-2019-15233 Advisory: advisory Basic Info Advisory ID: FAB-2019-00157 Product: Live Input Macros Manufacturer: Old Street Solutions Affected Version(s): 210 and before Tested Version(s): 210 Vulnerability Type: Cross-Site Scripting (CWE-79) Risk Level: High CVSS v30: 76 Vektor String: CVSS:30/AV:N/AC:L/PR:L/U