Files
CVEs-PoC/2019/CVE-2019-19089.md
2025-09-29 21:09:30 +02:00

899 B

CVE-2019-19089

Description

For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.

POC

Reference

Github

No PoCs found on GitHub currently.