Description
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.
No analysis available yet.
Remediation
Vendor Solution
Update your LXCA installation to version 2.6.6 or later. Installation note: You will need to update to LXCA 2.6.0 before installing the latest fix bundle (v 2.6.6).
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-9357 | An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-29477 |
|
History
No history.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-16T19:40:04.719Z
Reserved: 2019-12-12T00:00:00.000Z
Link: CVE-2019-19757
No data.
Status : Modified
Published: 2020-02-14T17:15:11.847
Modified: 2024-11-21T04:35:20.097
Link: CVE-2019-19757
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD