VYPR
Unrated severityNVD Advisory· Published Dec 17, 2018· Updated Aug 5, 2024

CVE-2018-19774

CVE-2018-19774

Description

Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "PresentSpace.jsp" has reflected XSS via the GroupId and ConnPoolName parameters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

InfoVista VistaPortal SE 5.1 (build 51029) suffers from a reflected XSS vulnerability in PresentSpace.jsp via GroupId and ConnPoolName parameters.

Vulnerability

A reflected cross-site scripting (XSS) vulnerability exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The issue is located in the PresentSpace.jsp page, where the GroupId and ConnPoolName parameters are not properly sanitized before being reflected back to the user. An attacker can inject arbitrary JavaScript code via these parameters, which will be executed in the context of the victim's browser session. [1]

Exploitation

An attacker can craft a malicious URL containing the XSS payload in either the GroupId or ConnPoolName parameter and trick a victim into clicking the link. No authentication is required to trigger the reflected XSS. The attacker does not need any special network position beyond delivering the link to the victim (e.g., via email, social media, or other means). [1]

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to session hijacking, credential theft, defacement, or redirection to malicious sites. The impact is limited to the browser context and does not directly compromise the server, but it can affect users of the VistaPortal application. [1]

Mitigation

As of the publication date (2018-12-17), no vendor patch or fix has been released for this vulnerability. Users should consider input validation and output encoding as a workaround, or restrict access to the affected page. The vulnerability is listed in the CVE database, but no fix version is known. [1]

References
  1. Packet Storm

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.