CVE-2019-25449
EUVD-2019-1958820.02.2026, 23:16
OrientDB 3.0.17 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted JSON payloads to the document endpoint. Attackers can send POST requests to /document/demodb/-1:-1 with script tags in the name parameter to execute arbitrary JavaScript in users' browsers.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| orientdb | orientdb | 3.0.17 |
𝑥
= Vulnerable software versions