Unrated severityNVD Advisory· Published May 17, 2020· Updated Aug 5, 2024
CVE-2019-20798
CVE-2019-20798
Description
An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. The XSS in the administrator panel can be used to reconfigure the server and execute arbitrary commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Cherokee/Cherokeedescription
- Range: <=1.2.104
Patches
Vulnerability mechanics
References
3- security.gentoo.org/glsa/202012-09mitrevendor-advisoryx_refsource_GENTOO
- github.com/cherokee/webserver/issues/1227mitrex_refsource_MISC
- logicaltrust.net/blog/2019/11/cherokee.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.