cbcvebase.
CVE-2019-5286
published 2019-06-13

CVE-2019-5286: There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit…

PriorityP426medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.71%
49.4th percentile
There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx Lite versions earlier than V200R006C00SPC007.

Affected

2 ranges
VendorProductVersion rangeFixed in
huaweihedex_lite< v200r006c00spc007v200r006c00spc007
huaweihedex_lite

CVSS provenance

nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.