Back to Database
Status published
Medium
CVE-2019-19856
An issue was discovered in Serpico (aka SimplE RePort wrIting...
Vulnerability Description
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-19856
Credits & Attribution
No credits recorded in the NVD database.
References
More from serpico project
View All →CVE-2020-12687
An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup...
Medium
6.5
CVE-2019-19859
An issue was discovered in Serpico (aka SimplE RePort wrIting...
Medium
5.3
CVE-2019-19858
An issue was discovered in Serpico (aka SimplE RePort wrIting...
Medium
4.8
CVE-2019-19857
An issue was discovered in Serpico (aka SimplE RePort wrIting...
Medium
6.5
CVE-2019-19855
An issue was discovered in Serpico (aka SimplE RePort wrIting...
Medium
4.8
Affected Vendor
serpico project
View all reports →Affected Software
serpico
Vulnerable Versions:
1.3.0
Timeline
Official Publish:
January 15th, 2020
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.