Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-19335

Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.5%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 2.6
Products affected by CVE-2018-19335
  • Google » Monorail » Version: 2018-04-04
    cpe:2.3:a:google:monorail:2018-04-04
  • Google » Monorail » Version: 2018-05-04
    cpe:2.3:a:google:monorail:2018-05-04


Contact Us

Shodan ® - All rights reserved