CVE-2019-15848

MEDIUM

JetBrains TeamCity 2019.1-2019.1.1 - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.

Scores

CVSS v3 6.1
EPSS 0.0001
EPSS Percentile 0.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
jetbrains/teamcity 2019.1
jetbrains/teamcity 2019.1.1
Published Sep 05, 2019
Tracked Since Feb 18, 2026