ArubaOS Web Components Vulnerable to HTTP Response Splitting and Reflected XSS via URL Parameters

ArubaOS Web Components Vulnerable to HTTP Response Splitting and Reflected XSS via URL Parameters

CVE-2019-5314 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.

Learn more about our Web App Pen Testing.