Telos Automated Message Handling System information disclosure in itemlookup.asp
Description
Telos AMHS versions prior to 4.1.5.5 contain an XSS vulnerability in itemlookup.asp that allows remote attackers to inject arbitrary script into an AMHS session, leading to information exposure and potential user data compromise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Telos AMHS versions prior to 4.1.5.5 contain an XSS vulnerability in itemlookup.asp that allows remote attackers to inject arbitrary script into an AMHS session, leading to information exposure and potential user data compromise.
Vulnerability
CVE-2019-9541 is a reflected cross-site scripting (XSS) vulnerability in the itemlookup.asp endpoint of the Telos Automated Message Handling System (AMHS), a web-based messaging system used by the DoD and Intelligence Community. The vulnerability exists in AMHS versions prior to 4.1.5.5 [1]. An attacker can craft a malicious URI that, when visited by an authenticated AMHS user, executes arbitrary JavaScript in the context of the user's session.
Exploitation
Exploitation requires no authentication from the attacker but does require a target user to click on a crafted link. The attacker sends a specially-crafted AMHS URI to an authenticated user (e.g., via email or other messaging). When the user accesses that URI within the AMHS web interface, the injected script executes in the user's browser session [1]. No special network position is required beyond the ability to deliver the link.
Impact
A successful attack can lead to information disclosure of other AMHS users' data, as the injected script can access the victim's session cookies and make requests on their behalf [1]. The attacker may also be able to perform actions with the victim's privileges. The CIA impact is partial confidentiality and integrity loss, with no direct impact on availability. The CVSS base score is 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N) [1].
Mitigation
The vulnerability is addressed in AMHS version 4.1.5.5 [1]. Users should contact Telos to obtain the update. No workaround is provided in the available references. The vulnerability is not currently listed on the CISA KEV.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2< 4.1.5.5+ 1 more
- (no CPE)range: < 4.1.5.5
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1- www.kb.cert.org/vuls/id/873161/mitrethird-party-advisoryx_refsource_CERT-VN
News mentions
0No linked articles in our index yet.