Back to Database
Status published
Critical
CVE-2019-14537
YOURLS through 1.7.3 is affected by a type juggling vulnerability...
Vulnerability Description
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-14537
Credits & Attribution
No credits recorded in the NVD database.
References
More from yourls
View All →CVE-2022-0088
Cross-Site Request Forgery (CSRF) in yourls/yourls
Low
3.5
CVE-2021-3785
Cross-site Scripting (XSS) - Stored in yourls/yourls
High
8.8
CVE-2021-3783
Cross-site Scripting (XSS) - Reflected in yourls/yourls
Medium
6.6
CVE-2021-3734
Improper Restriction of Rendered UI Layers or Frames in yourls/yourls
Medium
6.5
CVE-2020-27388
Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the...
Medium
5.4
Affected Vendor
yourls
View all reports →Affected Software
yourls
Vulnerable Versions:
0
Timeline
Official Publish:
August 7th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.