CVE-2019-14297
https://notcve.org/view.php?id=CVE-2019-14297
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx. ONE Reporter de Veeam versión 9.5.0.3201, permite a problema de tipo XSS por medio de la Widget de Agregar/Editar con un campo Caption diseñado para la función setDashboardWidget en archivo CommonDataHandlerReadOnly.ashx. • https://www.exploit-db.com/exploits/46767 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-11569 – Veeam ONE Reporter 9.5.0.3201 - Multiple Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2019-11569
Veeam ONE Reporter 9.5.0.3201 allows CSRF. Veeam ONE Reporter 9.5.0.3201 permite CSRF. Veeam ONE Reporter version 9.5.0.3201 suffers from multiple cross site request forgery vulnerabilities. • https://www.exploit-db.com/exploits/46765 • CWE-352: Cross-Site Request Forgery (CSRF) •