Skip to content

Cross site scripting attack in ServiceStack Framework

Moderate severity GitHub Reviewed Published May 24, 2022 to the GitHub Advisory Database • Updated Jan 27, 2023

Package

nuget ServiceStack (NuGet)

Affected versions

>= 4.5.14, < 5.2.0

Patched versions

5.2.0

Description

ServiceStack ServiceStack Framework 4.5.14 is affected by: Cross Site Scripting (XSS). The impact is: JavaScrpit is reflected in the server response, hence executed by the browser. The component is: the query used in the GET request is prone. The attack vector is: Since there is no server-side validation and If Browser encoding is bypassed, the victim is affected when opening a crafted URL. The fixed version is: 5.2.0.

References

Published by the National Vulnerability Database Jul 23, 2019
Published to the GitHub Advisory Database May 24, 2022
Reviewed Jun 17, 2022
Last updated Jan 27, 2023

Severity

Moderate
6.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CVE ID

CVE-2019-1010199

GHSA ID

GHSA-vcfc-9wcp-j623

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.