CVE-2019-15848

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
05/09/2019
Last modified:
18/09/2019

Description

JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jetbrains:teamcity:2019.1:-:*:*:*:*:*:*
cpe:2.3:a:jetbrains:teamcity:2019.1.1:*:*:*:*:*:*:*