VYPR
Medium severity5.4NVD Advisory· Published Jan 5, 2021· Updated Jun 17, 2026

CVE-2019-20483

CVE-2019-20483

Description

An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read another user's cookie and use that to login to the application.

Affected products

3
  • cpe:2.3:a:vikisolutions:vera:4.9.1.26180:*:*:*:*:*:*:*
  • Viki Vera/Viki Veradescription
  • Viki/Verallm-fuzzy
    Range: 4.9.1.26180

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.