VYPR
Unrated severityNVD Advisory· Published Dec 17, 2018· Updated Aug 5, 2024

CVE-2018-19649

CVE-2018-19649

Description

XSS exists in InfoVista VistaPortal SE Version 5.1 (build 51029). VPortal/mgtconsole/RolePermissions.jsp has reflected XSS via the ConnPoolName parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A reflected XSS vulnerability in InfoVista VistaPortal SE 5.1 (build 51029) exists in RolePermissions.jsp via the ConnPoolName parameter, allowing arbitrary script execution.

Vulnerability

A reflected cross-site scripting (XSS) vulnerability exists in InfoVista VistaPortal SE Version 5.1 (build 51029) in the VPortal/mgtconsole/RolePermissions.jsp endpoint. The ConnPoolName parameter is not properly sanitized before being reflected back to the user, allowing an attacker to inject arbitrary HTML or JavaScript [1].

Exploitation

The attacker must craft a malicious URL containing a payload in the ConnPoolName parameter and deliver it to a victim who is authenticated to the VistaPortal management console. No user interaction beyond clicking the link (or being redirected) is required. The payload is reflected immediately in the server response and executed in the victim's browser context [1].

Impact

Successful exploitation enables the attacker to execute arbitrary JavaScript in the context of the victim's session within the VistaPortal application. This can lead to session hijacking, defacement, or theft of sensitive information accessible within the management console. The attack does not require any special privileges beyond the victim having an active session [1].

Mitigation

As of the publication date, no vendor patch or workaround has been disclosed in the available references. The advisory from Packet Storm [1] indicates the vulnerability affects VistaPortal SE 5.1 (build 51029). It is recommended to apply any vendor updates or mitigations if they become available, and to restrict access to the management console to trusted networks.

References
  1. Packet Storm

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.