cve/2019/CVE-2019-25028.md
2024-05-26 14:27:05 +02:00

937 B

CVE-2019-25028

Description

Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 through 8.8.4 (Vaadin 8.0.0 through 8.8.4) allows attacker to inject malicious JavaScript via unspecified vector

POC

Reference

No PoCs from references.

Github