Security Advisory

CVE-2018-19509

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-03-17 21:49:26
Last updated 2024-08-05 11:37:11
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encoding. Because it is possible to insert arbitrary strings into the database, any JavaScript could be executed by the administrator, leading to XSS.