VYPR
Unrated severityNVD Advisory· Published May 23, 2019· Updated Aug 4, 2024

CVE-2019-10846

CVE-2019-10846

Description

Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Computrols CBAS 18.0.0 contains unauthenticated reflected XSS vulnerabilities in the login and password reset pages via the username parameter.

Vulnerability

Computrols CBAS version 18.0.0 is vulnerable to unauthenticated reflected cross-site scripting (XSS) in the login page and password reset page. The username GET parameter is not sanitized before being reflected in the response, allowing an attacker to inject arbitrary JavaScript. This issue is similar to the one reported for version 19.0.0 [3].

Exploitation

An attacker can craft a malicious URL containing a JavaScript payload in the username parameter. No authentication is required. The victim must be tricked into clicking the link; the script then executes in the context of the CBAS web interface, typically with the same privileges as the victim's session [3].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to session hijacking, credential theft, defacement, or other actions that the victim can perform within the CBAS application [3].

Mitigation

As of the publication date, no official patch has been disclosed for version 18.0.0. Users should monitor vendor updates and consider upgrading to a patched version if available. No workaround is mentioned in the available references [3].

References
  1. Packet Storm

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.