CVE-2019-20663
published 2020-04-15CVE-2019-20663: Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
PriorityP414medium4.3CVSS 3.1
AVAACLPRHUIRSCCLILAN
EPSS
0.30%
21.6th percentile
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | rbk50_firmware | < 2.3.5.30 | 2.3.5.30 |
| netgear | rbr50_firmware | < 2.3.5.30 | 2.3.5.30 |
| netgear | rbs50_firmware | < 2.3.5.30 | 2.3.5.30 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv3.06.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
nvdv2.02.3LOWAV:A/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h592-26mx-g23f: Certain NETGEAR devices are affected by stored XSS
ghsa_unreviewed·2022-05-24
CVE-2019-20663 [LOW] GHSA-h592-26mx-g23f: Certain NETGEAR devices are affected by stored XSS
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
GHSA
The Reporting Addon for CUBA Platform has Persistent XSS
ghsa·2022-05-14
CVE-2018-20663 [MEDIUM] CWE-79 The Reporting Addon for CUBA Platform has Persistent XSS
The Reporting Addon for CUBA Platform has Persistent XSS
The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-15
Published