CVE-2019-6181
published 2019-09-03CVE-2019-6181: A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted…
medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted URL, if visited, to cause JavaScript code to be executed in the user's web browser. The JavaScript code is not executed on LXCA itself.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | xclarity_administrator | < 2.5.0 | 2.5.0 |
| lenovo | xclarity_administrator | >= unspecified < 2.5.0 | 2.5.0 |