312
VMScore

CVE-2019-19912

Published: 30/03/2020 Updated: 18/10/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In Intland codeBeamer ALM 9.5 and previous versions, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote malicious users to inject arbitrary scripts via an active script embedded in an SWF file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intland codebeamer

Exploits

codeBeamer versions 95 and below suffer from multiple persistent cross site scripting vulnerabilities ...