Medium severity6.1NVD Advisory· Published Jun 4, 2020· Updated Jun 17, 2026
CVE-2019-16385
CVE-2019-16385
Description
Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a PDF, containing the malicious payload. This results in a reflected XSS payload being executed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:cybelesoft:thinfinity_virtualui:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cybelesoft:thinfinity_virtualui:*:*:*:*:*:*:*:*range: <=2.5.17.2
- (no CPE)range: = 2.5.17.2
- Cybele/Thinfinity VirtualUIdescription
Patches
Vulnerability mechanics
References
1- labs.nettitude.com/blog/cve-2019-16384-85-cyblesoft-thinfinity-virtualui-path-traversal-http-header-injection/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.