CVE-2019-18914 is a Cross-Site Scripting (XSS) vulnerability affecting certain HP printers and MFPs, allowing an attacker to inject malicious scripts into a client's browser if they click a crafted third-party link. Rated as MEDIUM severity with a CVSS score of 6.1, this vulnerability requires user interaction (clicking a malicious link) and could lead to limited confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2309025_582081CPE matchmatch criteria | cpe:2.3:o:hp:futuresmart_3:*:*:*:*:*:*:*:* | ||
< 2309025_582098CPE matchmatch criteria | cpe:2.3:o:hp:futuresmart_3:*:*:*:*:*:*:*:* | ||
< 2410028_055010CPE matchmatch criteria | cpe:2.3:o:hp:futuresmart_4:*:*:*:*:*:*:*:* | ||
< 2309025_582089CPE matchmatch criteria | cpe:2.3:o:hp:futuresmart_3:*:*:*:*:*:*:*:* | ||
< 2410028_055028CPE matchmatch criteria | cpe:2.3:o:hp:futuresmart_4:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.