6.1

CVE-2019-17120

Exploit

A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp. The usr parameter is vulnerable: the reflected cross-site scripting occurs immediately after the user is created. The malicious script is stored and will be executed whenever /WiKIDAdmin/adm_usrs.jsp is visited.

Data is provided by the National Vulnerability Database (NVD)
Wikidsystems2fa Enterprise Server Version3.4.81 Updateb676
Wikidsystems2fa Enterprise Server Version3.4.85 Updateb780
Wikidsystems2fa Enterprise Server Version3.4.87 Updateb1092
Wikidsystems2fa Enterprise Server Version3.4.87 Updateb1159
Wikidsystems2fa Enterprise Server Version3.4.87 Updateb1169
Wikidsystems2fa Enterprise Server Version3.4.87 Updateb1216
Wikidsystems2fa Enterprise Server Version3.4.87 Updateb824
Wikidsystems2fa Enterprise Server Version3.4.87 Updateb839
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1342
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1352
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1359
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1373
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1403
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1411
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1421
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1428
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1438
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1472
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1542
Wikidsystems2fa Enterprise Server Version3.5.0 Updateb1580
Wikidsystems2fa Enterprise Server Version3.6.0 Updateb1659
Wikidsystems2fa Enterprise Server Version3.6.0 Updateb1672
Wikidsystems2fa Enterprise Server Version4.0 Updateb1787
Wikidsystems2fa Enterprise Server Version4.0 Updateb1798
Wikidsystems2fa Enterprise Server Version4.0 Updateb1803
Wikidsystems2fa Enterprise Server Version4.0.1 Updateb1817
Wikidsystems2fa Enterprise Server Version4.0.1 Updateb1821
Wikidsystems2fa Enterprise Server Version4.0.1 Updateb1905
Wikidsystems2fa Enterprise Server Version4.0.1 Updateb1906
Wikidsystems2fa Enterprise Server Version4.0.2 Updateb1917
Wikidsystems2fa Enterprise Server Version4.0.2 Updateb1921
Wikidsystems2fa Enterprise Server Version4.1.0 Updateb1926
Wikidsystems2fa Enterprise Server Version4.1.0 Updateb1941
Wikidsystems2fa Enterprise Server Version4.1.0 Updateb1949
Wikidsystems2fa Enterprise Server Version4.1.0 Updateb1955
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb1978
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb1981
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb1984
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb2007
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb2014
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb2016
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb2020
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb2023
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb2028
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb2032
Wikidsystems2fa Enterprise Server Version4.2.0 Updateb2047
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.02% 0.897
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.