VYPR
Medium severity6.1NVD Advisory· Published Nov 18, 2019· Updated Jun 17, 2026

CVE-2019-12311

CVE-2019-12311

Description

Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a script could be uploaded to the server. When a victim tries to download a CISO Report template, the script is loaded.

Affected products

3
  • cpe:2.3:a:sandline:centraleyezer:-:*:*:*:on_premise:*:*:*+ 1 more
    • cpe:2.3:a:sandline:centraleyezer:-:*:*:*:on_premise:*:*:*
    • (no CPE)
  • Sandline/Centraleyezerdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.