CVE-2018-19774
Description
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "PresentSpace.jsp" has reflected XSS via the GroupId and ConnPoolName parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
InfoVista VistaPortal SE 5.1 (build 51029) suffers from a reflected XSS vulnerability in PresentSpace.jsp via GroupId and ConnPoolName parameters.
Vulnerability
A reflected cross-site scripting (XSS) vulnerability exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The issue is located in the PresentSpace.jsp page, where the GroupId and ConnPoolName parameters are not properly sanitized before being reflected back to the user. An attacker can inject arbitrary JavaScript code via these parameters, which will be executed in the context of the victim's browser session. [1]
Exploitation
An attacker can craft a malicious URL containing the XSS payload in either the GroupId or ConnPoolName parameter and trick a victim into clicking the link. No authentication is required to trigger the reflected XSS. The attacker does not need any special network position beyond delivering the link to the victim (e.g., via email, social media, or other means). [1]
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to session hijacking, credential theft, defacement, or redirection to malicious sites. The impact is limited to the browser context and does not directly compromise the server, but it can affect users of the VistaPortal application. [1]
Mitigation
As of the publication date (2018-12-17), no vendor patch or fix has been released for this vulnerability. Users should consider input validation and output encoding as a workaround, or restrict access to the affected page. The vulnerability is listed in the CVE database, but no fix version is known. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: = 5.1 (build 51029)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- packetstormsecurity.com/files/150690/VistaPortal-SE-5.1-Cross-Site-Scripting.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2018/Dec/20mitremailing-listx_refsource_FULLDISC
News mentions
0No linked articles in our index yet.