Back to CVE List

CVE-2019-25265

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.4 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Vulnerability Description

Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side script execution.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-79
Source
NVD
Vendor
Bigprof
Product
Online Inventory Manager

External References

Discussion (0)

Add Comment

No comments yet. Be the first!