Vulnerability Details CVE-2019-20483
An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read another user's cookie and use that to login to the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 41.0%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2019-20483
-
cpe:2.3:a:vikisolutions:vera:4.9.1.26180