« Volver al listado

CVE-2019-1010008

Estado: ModificadaMedia (5.4)—

OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent XSS (user could embed mal. code). The component is: Javascript code execution in "Name", "Location", "Bio" and "Starting Page" fields in the "My Account" page. File: Lib/listjs/list.js, line 67. The attack vector is: unknown, victim must open profile page if persistent was possible.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-1010008",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "josh@bress.net",
      "affectedData": [
        {
          "vendor": "OpenEnergyMonitor Project",
          "product": "Emoncms",
          "versions": [
            {
              "status": "affected",
              "version": "9.8.8"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-07-15T02:15:10.433",
  "references": [
    {
      "url": "https://github.com/emoncms/emoncms/issues/763",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "josh@bress.net"
    },
    {
      "url": "https://github.com/emoncms/emoncms/issues/763",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent XSS (user could embed mal. code). The component is: Javascript code execution in \"Name\", \"Location\", \"Bio\" and \"Starting Page\" fields in the \"My Account\" page. File: Lib/listjs/list.js, line 67. The attack vector is: unknown, victim must open profile page if persistent was possible."
    },
    {
      "lang": "es",
      "value": "Project Emoncms versión 9.8.8 de OpenEnergyMonitor, está afectado por: Cross Site Scripting (XSS). El impacto es: teóricamente bajo, pero potencialmente podría habilitar un problema de tipo XSS persistente (el usuario podría insertar código mal.). El componente es: ejecución de código Javascript en los campos \"Name\", \"Location\", \"Bio\" y \"Starting Page\" en la página \"My Account\".  Archivo: Lib/listjs/list.js, línea 67. El vector de ataque es: desconocido, la víctima debe abrir la página del perfil si fue posible la persistencia."
    }
  ],
  "lastModified": "2026-06-17T02:09:43.370",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openenergymonitor:emoncms:9.8.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "875613E0-4DC7-4485-AB1E-8DAF9313303E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "josh@bress.net"
}