Vulnerabilities (CVE)

Filtered by vendor Trustwave Subscribe
Filtered by product Modsecurity
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-25043 1 Trustwave 1 Modsecurity 2021-05-14 5.0 MEDIUM 5.3 MEDIUM
ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.
CVE-2018-13065 1 Trustwave 1 Modsecurity 2021-02-10 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured.