Medium severity6.1NVD Advisory· Published Mar 21, 2019· Updated Jun 17, 2026
CVE-2019-7417
CVE-2019-7417
Description
XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:ericsson:active_library_explorer:14.3:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ericsson:active_library_explorer:14.3:*:*:*:*:*:*:*
- (no CPE)range: =14.3
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/151583/Ericsson-Active-Library-Explorer-ALEX-14.3-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2019/Feb/27nvdExploitMailing ListThird Party Advisory
- www.ericsson.comnvdProduct
News mentions
0No linked articles in our index yet.