CVE-2019-3911
LabKey Server Community Edition <18.3.0 - Cross-Site Scripting
Record summary
CVE-2019-3911 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror parameter in the /__r2/query endpoints.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
LabKey Server Community EditionBrowse Tenable / LabKey Server Community Edition | CVE List | Versions before 18.3.0-61806.763 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMLabKey Server Community Edition <18.3.0 - Cross-Site ScriptingCVSS 6.1
LabKey Server Community Edition before 18.3.0-61806.763 contains a reflected cross-site scripting vulnerability via the onerror parameter in the /__r2/query endpoints, which allows an unauthenticated remote attacker to inject arbitrary JavaScript.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade LabKey Server Community Edition to version 18.3.0 or later to mitigate this vulnerability.
Source: ProjectDiscovery