CVE-2019-18249

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
24/12/2019
Last modified:
07/01/2020

Description

Reliable Controls MACH-ProWebCom/Sys, all versions prior to 2.15 (Firmware versions prior to 8.26.4), may allow attacker to execute commands on behalf of the user when an authenticated user clicks on a malicious link.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:reliablecontrols:mach-prowebsys_firmware:*:*:*:*:*:*:*:* 8.26.4 (excluding)
cpe:2.3:h:reliablecontrols:mach-prowebsys:*:*:*:*:*:*:*:* 2.15 (excluding)
cpe:2.3:o:reliablecontrols:mach-prowebcom_firmware:*:*:*:*:*:*:*:* 8.26.4 (excluding)
cpe:2.3:h:reliablecontrols:mach-prowebcom:*:*:*:*:*:*:*:* 2.15 (excluding)


References to Advisories, Solutions, and Tools