cve/2019/CVE-2019-11274.md

18 lines
819 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-11274](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11274)
![](https://img.shields.io/static/v1?label=Product&message=UAA%20Release%20(OSS)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%3A%20Cross-site%20Scripting%20(XSS)%20-%20Generic&color=brighgreen)
### Description
Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that contains a SCIM filter that contains malicious JavaScript, which older browsers may execute.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/tuhh-softsec/A-Manually-Curated-Dataset-of-Vulnerability-Introducing-Commits-in-Java