Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-0186

The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate to version 3.1.0 of the chat-room-demo war file
Exploit prediction scoring system (EPSS) score
EPSS Score 0.08
EPSS Ranking 91.6%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
References
Products affected by CVE-2019-0186
  • Apache » Pluto » Version: 3.0.0
    cpe:2.3:a:apache:pluto:3.0.0
  • Apache » Pluto » Version: 3.0.1
    cpe:2.3:a:apache:pluto:3.0.1


Contact Us

Shodan ® - All rights reserved