CVE-2019-7551: Cantemo Portal

Critical severity, CVSS 9.0. EPSS: 1.7% chance of exploitation in the next 30 days.

Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.

Affected products

  • Cantemo Portal: before 3.2.13 (fixed in 3.2.13); from 3.3.0, before 3.3.8 (fixed in 3.3.8); from 3.4.0, before 3.4.9 (fixed in 3.4.9)

Published 2019-04-10. Last modified 2026-06-17.