CVE-2019-11776

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/08/2019
Last modified:
18/12/2020

Description

In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:business_intelligence_and_reporting_tools:*:*:*:*:*:*:*:* 1.0.0 (including) 4.7.0 (including)


References to Advisories, Solutions, and Tools