CVE-2019-7169 describes a stored self-XSS vulnerability in Croogo through version 3.0.5, specifically within the Title field of the /admin/menus/menus/edit/3 page. This medium-severity vulnerability (CVSS 4.8) allows a highly privileged attacker to execute arbitrary HTML or JavaScript code in the victim's browser, requiring user interaction. While the potential impact is limited to low confidentiality and integrity, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.5CPE matchmatch criteria | cpe:2.3:a:croogo:croogo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.