VYPR
Medium severity5.4NVD Advisory· Published Jan 5, 2021· Updated Jun 17, 2026

CVE-2019-20483

CVE-2019-20483

Description

An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read another user's cookie and use that to login to the application.

Affected products

2
  • Viki Vera/Viki Veradescription
  • Viki/Verallm-fuzzy
    Range: 4.9.1.26180

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.