{"id":"CVE-2019-0186","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-0186","summary":"Cross-site Scripting in Apache Pluto Chatroom demo","details":"The input fields of the Apache Pluto \"Chat Room\" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate to version 3.1.0 of the chat-room-demo war file","published":"2022-05-24T16:44:43Z","modified":"2024-02-18T05:21:20.977509Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.portals.pluto:chatRoomDemo","fixedVersion":"3.1.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-0186"},{"type":"WEB","url":"https://lists.apache.org/thread.html/d093e6b0e5f9b3b50928255451afefd8f8fbdcd5bf28a726769a919a@%3Cpluto-user.portals.apache.org%3E"},{"type":"WEB","url":"https://portals.apache.org/pluto/security.html"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/46759"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2019/04/25/8"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/portals-pluto-user/201904.mbox/%3CCAAqbB_ev=0KNgZmmNAq2=q11i1GYLGN6J-xCKx8Q8dbxZ4tZYg@mail.gmail.com%3E"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-18T05:21:20.977509Z"}}