Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zhesun88

#43019of 53,632
6.1Total CVSS
Vulnerabilities · 1
PT-2021-9095
6.1
2021-04-19
Vaadin · Vaadin-Server · CVE-2019-25028
**Name of the Vulnerable Software and Affected Versions** com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 com.vaadin:vaadin-server versions 8.0.0 through 8.8.4 **Description** The issue is related to missing variable sanitization in the Grid component, allowing an attacker to inject malicious JavaScript via an unspecified vector. **Recommendations** For versions 7.4.0 through 7.7.19, update to a version outside of this range to mitigate the risk. For versions 8.0.0 through 8.8.4, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting the use of the Grid component until a patch is available.