CVE-2019-14478 describes a stored Cross-Site Scripting (XSS) vulnerability in AdRem NetCrunch 10.6.0.4587. An attacker can inject malicious JavaScript into the "Display Name" field, which executes in a victim's browser when they view or search for the compromised node. Rated Medium (CVSS 5.4), this vulnerability requires user interaction (UI:R) and authenticated access (PR:L), potentially leading to limited confidentiality and integrity impact (C:L/I:L). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.6.0.4587CPE matchmatch criteria | cpe:2.3:a:adremsoft:netcrunch:10.6.0.4587:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.