Medium severity6.1NVD Advisory· Published Mar 25, 2019· Updated Jun 17, 2026
CVE-2019-10016
CVE-2019-10016
Description
GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.
Affected products
2cpe:2.3:a:gforge:advanced_server:6.4.4:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gforge:advanced_server:6.4.4:*:*:*:*:*:*:*
- (no CPE)range: = 6.4.4
Patches
Vulnerability mechanics
References
1- ctrsec.io/index.php/2019/03/24/gforge-advanced-server-xss-commonsearch-php/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.