VYPR
Medium severity6.1NVD Advisory· Published Jan 28, 2020· Updated Jun 17, 2026

CVE-2019-10779

CVE-2019-10779

Description

All versions of stroom:stroom-app before 5.5.12 and all versions of the 6.0.0 branch before 6.0.25 are affected by Cross-site Scripting. An attacker website is able to load the Stroom UI into a hidden iframe. Using that iframe, the attacker site can issue commands to the Stroom UI via an XSS vulnerability to take full control of the Stroom UI on behalf of the logged-in user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:gchq:stroom:*:*:*:*:*:*:*:*
    Range: <5.5.12
  • stroom/stroom-appdescription
  • Range: <5.5.12, <6.0.25

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.