CVE Published: 30/11/2022 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: icscert |
Vendor: Digital Alert Systems |
Product: DASDEC Status : PUBLISHED
CVE-2019-18265 Description
Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.
Metrics
CVSS Version: 3.1 |
Base Score: 4.7 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N