← Back

CVE-2019-17120

nvd nist
Published: Oct 17, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp. The usr parameter is vulnerable: the reflected cross-site scripting occurs immediately after the user is created. The malicious script is stored and will be executed whenever /WiKIDAdmin/adm_usrs.jsp is visited.

Affected (46)

1 product
2fa Enterprise Server
Configuration A
46 vulnerable
Vulnerable SoftwareAffected Versions
Wikidsystems
Version 3.4.81 b676
Version 3.4.85 b780
Version 3.4.87 b1092
Version 3.4.87 b1159
Version 3.4.87 b1169
Version 3.4.87 b1216
Version 3.4.87 b824
Version 3.4.87 b839
Version 3.5.0 b1342
Version 3.5.0 b1352
Version 3.5.0 b1359
Version 3.5.0 b1373
Version 3.5.0 b1403
Version 3.5.0 b1411
Version 3.5.0 b1421
Version 3.5.0 b1428
Version 3.5.0 b1438
Version 3.5.0 b1472
Version 3.5.0 b1542
Version 3.5.0 b1580
Version 3.6.0 b1659
Version 3.6.0 b1672
Version 4.0.1 b1817
Version 4.0.1 b1821
Version 4.0.1 b1905
Version 4.0.1 b1906
Version 4.0.2 b1917
Version 4.0.2 b1921
Version 4.0 b1787
Version 4.0 b1798
Version 4.0 b1803
Version 4.1.0 b1926
Version 4.1.0 b1941
Version 4.1.0 b1949
Version 4.1.0 b1955
Version 4.2.0 b1978
Version 4.2.0 b1981
Version 4.2.0 b1984
Version 4.2.0 b2007
Version 4.2.0 b2014
Version 4.2.0 b2016
Version 4.2.0 b2020
Version 4.2.0 b2023
Version 4.2.0 b2028
Version 4.2.0 b2032
Version 4.2.0 b2047

References (6)

Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.