← back
CVE-2019-3686mediumCWE-79

XSS in distri and version parameter in openQA

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.6%
exploitation probability
0.6%top 52% of all CVEs
observed exploitation
nono source reports it
openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27b was vulnerable to XSS in the distri and version parameter. This was reported through the bug bounty program of Offensive Security
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
SUSE · openQA