Record summary

CVE-2019-3911 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror parameter in the /__r2/query endpoints.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListVersions before 18.3.0-61806.763affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLabKey Server Community Edition <18.3.0 - Cross-Site ScriptingCVSS 6.1

LabKey Server Community Edition before 18.3.0-61806.763 contains a reflected cross-site scripting vulnerability via the onerror parameter in the /__r2/query endpoints, which allows an unauthenticated remote attacker to inject arbitrary JavaScript.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade LabKey Server Community Edition to version 18.3.0 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsprincechaddha
Template tagscvecve2019xsslabkeytenablevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:labkey:labkey_server:*:*:community:*:*:*:*:*
Shodan: Server: Labkey
Shodan: http.title:"sign in: /home"
Shodan: server: labkey
FOFA: title="sign in: /home"
Google: intitle:"sign in: /home"

Source: ProjectDiscovery

References

2