CVE-2019-13189: Eng Knowage

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.

Affected products

  • Eng Knowage: before 6.4 (fixed in 6.4)

Published 2019-08-28. Last modified 2026-06-17.