Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3.1.1 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
References
Link | Resource |
---|---|
http://jvn.jp/en/jp/JVN40288903/index.html | Third Party Advisory |
https://dradisframework.com/ce/security_reports.html#fixed-3.11.1 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jpcert
Published: 2019-03-12T21:00:00
Updated: 2019-03-12T20:57:01
Reserved: 2019-01-10T00:00:00
Link: CVE-2019-5925
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-03-12T22:29:01.270
Modified: 2019-03-13T14:06:53.947
Link: CVE-2019-5925
JSON object: View
Redhat Information
No data.
CWE