← All CVEs

CVE-2019-10092

medium · 6.1

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

6.1
CVSS
81.5%
EPSS (exploit prob.)
100th
EPSS percentile
2019-09-26
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
apachehttp_server>= 2.4.0, <= 2.4.39
opensuseleap15.0
opensuseleap15.1
debiandebian_linux8.0
debiandebian_linux9.0
debiandebian_linux10.0
redhatsoftware_collection1.0
fedoraprojectfedora30
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux19.04
netappclustered_data_ontap<= 9.5
netappclustered_data_ontap9.6
netappclustered_data_ontap9.6
netappclustered_data_ontap9.6
netappclustered_data_ontap9.6
netappclustered_data_ontap9.6
netappclustered_data_ontap9.6
oraclecommunications_element_manager8.0.0
oraclecommunications_element_manager8.1.0
oraclecommunications_element_manager8.1.1
oraclecommunications_element_manager8.2.0
oracleenterprise_manager_ops_center12.3.3
oracleenterprise_manager_ops_center12.4.0
oraclesecure_global_desktop5.4
oraclesecure_global_desktop5.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-10092