VYPR
Unrated severityNVD Advisory· Published Dec 17, 2018· Updated Aug 5, 2024

CVE-2018-19765

CVE-2018-19765

Description

Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentPresentSpace.jsp" has reflected XSS via the ConnPoolName, GroupId, and ParentId parameters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in InfoVista VistaPortal SE 5.1 EditCurrentPresentSpace.jsp via multiple parameters allows arbitrary script execution.

Vulnerability

InfoVista VistaPortal SE Version 5.1 (build 51029) is affected by a reflected Cross-Site Scripting (XSS) vulnerability in the EditCurrentPresentSpace.jsp page [1]. The parameters ConnPoolName, GroupId, and ParentId are not properly sanitized before being reflected back to the user, allowing injection of arbitrary HTML and JavaScript.

Exploitation

An attacker can exploit this vulnerability by crafting a malicious URL containing a JavaScript payload in one of the vulnerable parameters and tricking a victim into clicking the link [1]. No special privileges or authentication are required; the victim simply must be logged into the application for the script to execute in the context of their session.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the security context of the VistaPortal application [1]. This could lead to session hijacking, credential theft, defacement, or other malicious actions depending on the application's functionality.

Mitigation

No mitigation or patch has been disclosed in the available reference [1]. Administrators should monitor for vendor updates and consider applying input validation or web application firewall rules as a temporary workaround.

References
  1. Packet Storm

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.