CVE-2018-19649
Description
XSS exists in InfoVista VistaPortal SE Version 5.1 (build 51029). VPortal/mgtconsole/RolePermissions.jsp has reflected XSS via the ConnPoolName parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A reflected XSS vulnerability in InfoVista VistaPortal SE 5.1 (build 51029) exists in RolePermissions.jsp via the ConnPoolName parameter, allowing arbitrary script execution.
Vulnerability
A reflected cross-site scripting (XSS) vulnerability exists in InfoVista VistaPortal SE Version 5.1 (build 51029) in the VPortal/mgtconsole/RolePermissions.jsp endpoint. The ConnPoolName parameter is not properly sanitized before being reflected back to the user, allowing an attacker to inject arbitrary HTML or JavaScript [1].
Exploitation
The attacker must craft a malicious URL containing a payload in the ConnPoolName parameter and deliver it to a victim who is authenticated to the VistaPortal management console. No user interaction beyond clicking the link (or being redirected) is required. The payload is reflected immediately in the server response and executed in the victim's browser context [1].
Impact
Successful exploitation enables the attacker to execute arbitrary JavaScript in the context of the victim's session within the VistaPortal application. This can lead to session hijacking, defacement, or theft of sensitive information accessible within the management console. The attack does not require any special privileges beyond the victim having an active session [1].
Mitigation
As of the publication date, no vendor patch or workaround has been disclosed in the available references. The advisory from Packet Storm [1] indicates the vulnerability affects VistaPortal SE 5.1 (build 51029). It is recommended to apply any vendor updates or mitigations if they become available, and to restrict access to the management console to trusted networks.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: = 5.1 (build 51029)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- packetstormsecurity.com/files/150690/VistaPortal-SE-5.1-Cross-Site-Scripting.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2018/Dec/20mitremailing-listx_refsource_FULLDISC
News mentions
0No linked articles in our index yet.