VYPR
Medium severity6.1NVD Advisory· Published Jun 4, 2020· Updated Jun 17, 2026

CVE-2019-16385

CVE-2019-16385

Description

Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a PDF, containing the malicious payload. This results in a reflected XSS payload being executed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:cybelesoft:thinfinity_virtualui:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cybelesoft:thinfinity_virtualui:*:*:*:*:*:*:*:*range: <=2.5.17.2
    • (no CPE)range: = 2.5.17.2
  • Cybele/Thinfinity VirtualUIdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.