Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25367. PoCs published by Ozer Goker.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in ArangoDB Community Edition 3.4.2-1, including DOM-based, reflected, and stored XSS. The PoC provides specific URLs, payloads, and parameters to trigger the vulnerabilities.
Description
ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated users' browsers.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in ArangoDB Community Edition 3.4.2-1, including DOM-based, reflected, and stored XSS. The PoC provides specific URLs, payloads, and parameters to trigger the vulnerabilities.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N