CVE-2019-7671 EXPLOIT
9.0
CRITICAL · CVSS 3.1 · EPSS 8.1% (pctl 95)
Patch early
A public exploit exists.
Description
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.
Scoring
| CVSS | 9.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
| EPSS | 8.11% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-06-05 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| primasystems | flexair |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting | 2019-11-12 |
References
- http://packetstormsecurity.com/files/155274/Prima-Access-Control-2.3.35-Cross-Site-Scripting.html
- https://applied-risk.com/index.php/download_file/view/199/165
- https://applied-risk.com/labs/advisories
- https://applied-risk.com/resources/ar-2019-007
- https://www.us-cert.gov/ics/advisories/icsa-19-211-02
- http://packetstormsecurity.com/files/155274/Prima-Access-Control-2.3.35-Cross-Site-Scripting.html
- https://applied-risk.com/index.php/download_file/view/199/165
- https://applied-risk.com/labs/advisories
- https://applied-risk.com/resources/ar-2019-007
- https://www.us-cert.gov/ics/advisories/icsa-19-211-02
→ the Explorer · watch your stack · NVD