CVE-2018-19765
Description
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentPresentSpace.jsp" has reflected XSS via the ConnPoolName, GroupId, and ParentId parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in InfoVista VistaPortal SE 5.1 EditCurrentPresentSpace.jsp via multiple parameters allows arbitrary script execution.
Vulnerability
InfoVista VistaPortal SE Version 5.1 (build 51029) is affected by a reflected Cross-Site Scripting (XSS) vulnerability in the EditCurrentPresentSpace.jsp page [1]. The parameters ConnPoolName, GroupId, and ParentId are not properly sanitized before being reflected back to the user, allowing injection of arbitrary HTML and JavaScript.
Exploitation
An attacker can exploit this vulnerability by crafting a malicious URL containing a JavaScript payload in one of the vulnerable parameters and tricking a victim into clicking the link [1]. No special privileges or authentication are required; the victim simply must be logged into the application for the script to execute in the context of their session.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the security context of the VistaPortal application [1]. This could lead to session hijacking, credential theft, defacement, or other malicious actions depending on the application's functionality.
Mitigation
No mitigation or patch has been disclosed in the available reference [1]. Administrators should monitor for vendor updates and consider applying input validation or web application firewall rules as a temporary workaround.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: =5.1 (build 51029)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- packetstormsecurity.com/files/150690/VistaPortal-SE-5.1-Cross-Site-Scripting.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2018/Dec/20mitremailing-listx_refsource_FULLDISC
News mentions
0No linked articles in our index yet.