Vulnerability record · CVE-2019-13345 · published 5 July 2019
CVE-2019-13345: Squid cachemgr.cgi reflected XSS via user_name and auth parameters
Squid Cache · Squid
The cachemgr.cgi web module in Squid through 4.7 reflects the user_name or auth parameter without proper output encoding, allowing reflected cross-site scripting. Because cachemgr.cgi is a management interface, successful exploitation can run script in the context of an authenticated administrator's browser.
Description
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (6.1) and it requires user interaction, but the very high EPSS score and public exploit tag raise the practical risk for exposed management interfaces.
What it is
The cachemgr.cgi web module in Squid through 4.7 reflects the user_name or auth parameter without proper output encoding, allowing reflected cross-site scripting. Because cachemgr.cgi is a management interface, successful exploitation can run script in the context of an authenticated administrator's browser.
Impact
An attacker can execute arbitrary JavaScript in a victim's browser session, potentially stealing session data or performing actions as the management user. The CVSS scope change (S:C) reflects that impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network via HTTP requests to cachemgr.cgi with crafted user_name or auth parameters. No authentication is required to deliver the payload, but the victim must be induced to click a crafted link (UI:R).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.74477, 99.5th percentile) and a vendor bug report is tagged Exploit, indicating public exploit interest. No ransomware association is documented.
What to do
- Upgrade Squid to a version later than 4.7 that includes the fix from PR 429, or apply the vendor patch for your distribution.
- Restrict access to cachemgr.cgi to trusted management networks and require authentication.
- Disable or remove cachemgr.cgi if it is not needed.
- Apply available distribution updates (Debian DSA-4507, Ubuntu USN-4059-1/2, Red Hat RHSA-2019:3476, openSUSE, Fedora).
Detection
- Inspect web and proxy logs for requests to cachemgr.cgi containing script tags or encoded payloads in user_name or auth parameters.
- Monitor for anomalous access to cachemgr.cgi from unexpected source addresses.
- Review browser or endpoint telemetry for script execution originating from cachemgr.cgi responses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-13345 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-13345), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.