PT-2019-15555 · Avast · Avast Antivirus
Yokokho
·
Published
2019-11-01
·
Updated
2019-11-06
·
CVE-2019-18653
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Avast AntiVirus versions 19.3.2369 build 19.3.4241.440
Description
A Cross Site Scripting (XSS) issue exists in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.
Recommendations
For Avast AntiVirus version 19.3.2369 build 19.3.4241.440, consider disabling the Network Notification Popup feature until a patch is available to prevent potential exploitation of the XSS issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avast Antivirus