CVE-2019-10846
Description
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Computrols CBAS 18.0.0 contains unauthenticated reflected XSS vulnerabilities in the login and password reset pages via the username parameter.
Vulnerability
Computrols CBAS version 18.0.0 is vulnerable to unauthenticated reflected cross-site scripting (XSS) in the login page and password reset page. The username GET parameter is not sanitized before being reflected in the response, allowing an attacker to inject arbitrary JavaScript. This issue is similar to the one reported for version 19.0.0 [3].
Exploitation
An attacker can craft a malicious URL containing a JavaScript payload in the username parameter. No authentication is required. The victim must be tricked into clicking the link; the script then executes in the context of the CBAS web interface, typically with the same privileges as the victim's session [3].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to session hijacking, credential theft, defacement, or other actions that the victim can perform within the CBAS application [3].
Mitigation
As of the publication date, no official patch has been disclosed for version 18.0.0. Users should monitor vendor updates and consider upgrading to a patched version if available. No workaround is mentioned in the available references [3].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Computrols/CBASdescription
- Range: = 18.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/155257/Computrols-CBAS-Web-19.0.0-Cross-Site-Scripting.htmlmitrex_refsource_MISC
- applied-risk.com/index.php/download_file/view/196/165mitrex_refsource_MISC
- applied-risk.com/labs/advisoriesmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.