Vulnerability Details CVE-2019-18378
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.0%
CVSS Severity
CVSS v3 Score 4.8
CVSS v2 Score 3.5
Products affected by CVE-2019-18378
-
cpe:2.3:a:symantec:messaging_gateway:10.0
-
cpe:2.3:a:symantec:messaging_gateway:10.0.1
-
cpe:2.3:a:symantec:messaging_gateway:10.0.2
-
cpe:2.3:a:symantec:messaging_gateway:10.0.3
-
cpe:2.3:a:symantec:messaging_gateway:10.5.0
-
cpe:2.3:a:symantec:messaging_gateway:10.5.1
-
cpe:2.3:a:symantec:messaging_gateway:10.5.2
-
cpe:2.3:a:symantec:messaging_gateway:10.5.4
-
cpe:2.3:a:symantec:messaging_gateway:10.6.0
-
cpe:2.3:a:symantec:messaging_gateway:10.6.1
-
cpe:2.3:a:symantec:messaging_gateway:10.6.2
-
cpe:2.3:a:symantec:messaging_gateway:10.6.3
-
cpe:2.3:a:symantec:messaging_gateway:10.6.4
-
cpe:2.3:a:symantec:messaging_gateway:10.6.5
-
cpe:2.3:a:symantec:messaging_gateway:10.6.6
-
cpe:2.3:a:symantec:messaging_gateway:10.7.0
-
cpe:2.3:a:symantec:messaging_gateway:9.5
-
cpe:2.3:a:symantec:messaging_gateway:9.5.1
-
cpe:2.3:a:symantec:messaging_gateway:9.5.2
-
cpe:2.3:a:symantec:messaging_gateway:9.5.3
-
cpe:2.3:a:symantec:messaging_gateway:9.5.4