VDB
CVE-2019-1010311
CVE-2019-1010311
PUBLISHED
Tildeslash Monit Version 5.25.2 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Execute javascript in a victim s browser; disable all monitoring for a particular host or service. The component is: In function do_viewlog() on line 910 in Monit/src/http/cervlet.c, an attacker controlled log file is copied into an HTTP response without any HTML escaping. The attack vector is: An authenticated remote attacker can exploit the vulnerability over a network. The fixed version is: Version 5.25.3 and later.
EPSS 0.24% · 64.0th percentile
Risk Scores
EPSS Score
0.24%
64.0th percentile
Timeline
- Jul 13, 2019 CVE Rejected
- Jul 13, 2019 CVE Updated
- Feb 8, 2024 EPSS Score
- Feb 22, 2024 EPSS Score
- Mar 7, 2024 EPSS Score
- Mar 20, 2024 EPSS Score
- Apr 3, 2024 EPSS Score
- Apr 17, 2024 EPSS Score
- May 1, 2024 EPSS Score
- May 15, 2024 EPSS Score
- May 29, 2024 EPSS Score
- Jun 11, 2024 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-1010311 advisory
- https://bitbucket.org/tildeslash/monit/commits/1a8295eab6815072a18019b668fe084945b751f3 url
- https://bitbucket.org/tildeslash/monit/commits/328f60773057641c4b2075fab9820145e95b728c url
- https://github.com/dzflack/exploits/blob/master/unix/monit_xss.py url