CVE-2019-13066: Sahipro Sahi Pro
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS.
Affected products
- Sahipro Sahi Pro: version 8.0.0 only
Published 2019-10-29. Last modified 2026-06-17.