Sploitus

CVE-2019-20798

No indexed exploits for CVE-2019-20798 yet

An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. The XSS in the administrator panel can be used to reconfigure the server and execute arbitrary commands.

Affected products
Cherokee
Cherokee-project Cherokee
≤ 1.2.104
Fix
Available
CVSS 3.1
8.4 HIGH
EPSS
1.7% (74th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2020-05-17
CVE-2019-20798 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2019-20798 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2019-20798 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.