CVE-2019-11776

MEDIUM

Eclipse BIRT 1.0-4.7 - Reflected Cross-Site Scripting via URL Parameter

Title source: llm
STIX 2.1

Description

In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.

References (1)

Core 1
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546816

Scores

CVSS v3 6.1
EPSS 0.0025
EPSS Percentile 48.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
eclipse/business_intelligence_and_reporting_tools 1.0.0 - 4.7.0
Published Aug 09, 2019
Tracked Since Feb 18, 2026