CVE-2019-10085

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
19/06/2019
Last modified:
07/11/2023

Description

In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS executes when a user engages with that dropdown on that page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:allura:*:*:*:*:*:*:*:* 1.11.0 (excluding)