CVE-2019-18209 is a Cross-Site Scripting (XSS) vulnerability affecting Etherpad-Lite version 1.7.5, specifically within the templates/pad.html component. This medium-severity vulnerability (CVSS 6.1) can be exploited when a browser, such as Internet Explorer, fails to properly encode the URL path, allowing an attacker to inject malicious scripts. While it has a low EPSS score and no known public exploits or active exploitation, successful exploitation could lead to limited confidentiality and integrity impacts. There is no evidence of community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.5CPE matchmatch criteria | cpe:2.3:a:etherpad:etherpad:1.7.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.