CVE-2019-25449
MEDIUMOrientDB 3.0.17 - Reflected Cross-Site Scripting via Document Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25449. PoCs published by Ozer Goker.
AI-analyzed exploit summary This is a detailed technical writeup describing multiple CSRF and XSS vulnerabilities in OrientDB 3.0.17 GA Community Edition. It includes HTTP request examples for exploiting these vulnerabilities but does not contain functional exploit code.
Description
OrientDB 3.0.17 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted JSON payloads to the document endpoint. Attackers can send POST requests to /document/demodb/-1:-1 with script tags in the name parameter to execute arbitrary JavaScript in users' browsers.
Exploits (1)
This is a detailed technical writeup describing multiple CSRF and XSS vulnerabilities in OrientDB 3.0.17 GA Community Edition. It includes HTTP request examples for exploiting these vulnerabilities but does not contain functional exploit code.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N