Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-10178
HistoryMar 18, 2020 - 4:15 p.m.

Cross site scripting

2020-03-1816:15:00
PRIOn knowledge base
www.prio-n.com

0.001 Low

EPSS

Percentile

35.9%

It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the “Activity” page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser. All versions of pki-core are believed to be vulnerable.

0.001 Low

EPSS

Percentile

35.9%