Vulnerability record · CVE-2019-17120 · published 17 October 2019
CVE-2019-17120: WiKID 2FA Enterprise Server stored and reflected XSS in adm_usrs.jsp
WWikidsystems · 2fa Enterprise Server
WiKID 2FA Enterprise Server through 4.2.0-b2047 is vulnerable to stored and reflected cross-site scripting via the usr parameter of /WiKIDAdmin/adm_usrs.jsp. The reflected payload fires immediately after user creation, and the script is then stored and executed whenever the page is visited. Because this is the administrative user-management interface of an authentication server, script execution there can compromise admin sessions and the 2FA platform itself.
Description
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp. The usr parameter is vulnerable: the reflected cross-site scripting occurs immediately after the user is created. The malicious script is stored and will be executed whenever /WiKIDAdmin/adm_usrs.jsp is visited.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityPublic exploit code and a very high EPSS score raise the likelihood of attempts, and successful XSS in the 2FA administration console can undermine the authentication platform itself.
What it is
WiKID 2FA Enterprise Server through 4.2.0-b2047 is vulnerable to stored and reflected cross-site scripting via the usr parameter of /WiKIDAdmin/adm_usrs.jsp. The reflected payload fires immediately after user creation, and the script is then stored and executed whenever the page is visited. Because this is the administrative user-management interface of an authentication server, script execution there can compromise admin sessions and the 2FA platform itself.
Impact
An attacker can run arbitrary script or HTML in the browser of an authenticated administrator viewing the user administration page, enabling session theft, credential capture or unauthorized administrative actions. The stored variant means the payload persists and re-executes on later visits without further attacker action.
Attack surface
Reached over the network through the WiKIDAdmin web interface at /WiKIDAdmin/adm_usrs.jsp, with the payload supplied in the usr parameter. The CVSS vector indicates no privileges are required (PR:N) but user interaction is required (UI:R), so an administrator must be induced to create or view the affected user entry.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded. EPSS is high (0.49955, 98.8th percentile) and all three references are tagged Exploit, indicating public proof-of-concept code exists.
What to do
- Upgrade WiKID 2FA Enterprise Server past 4.2.0-b2047 to a fixed release; the record does not name a fixed version, so confirm with the vendor.
- If patching is delayed, restrict network access to /WiKIDAdmin/ to trusted management networks or VPN.
- Encode or reject the usr parameter on input and output, and apply a strict Content-Security-Policy to the admin interface.
- Require administrators to re-authenticate and rotate sessions and credentials after any suspected exposure.
- Review the admin interface for other unescaped parameters in the same JSP and related pages.
Detection
- Search web and proxy logs for requests to /WiKIDAdmin/adm_usrs.jsp containing script tags or event handlers in the usr parameter.
- Monitor for unexpected script content stored in WiKID user records or rendered on the admin user page.
- Alert on anomalous admin session activity, such as new admin accounts or configuration changes following visits to adm_usrs.jsp.
- Correlate outbound requests from administrator browsers to unfamiliar domains shortly after admin page access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/154912/WiKID-Systems-2FA-Enterprise-Server-4.2.0-b2032-SQL-Injection-XSS-CSRF.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/Oct/35 | ExploitMailing ListThird Party Advisory |
| https://www.securitymetrics.com/blog/wikid-2fa-enterprise-server-cross-site-scripting | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/154912/WiKID-Systems-2FA-Enterprise-Server-4.2.0-b2032-SQL-Injection-XSS-CSRF.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/Oct/35 | ExploitMailing ListThird Party Advisory |
| https://www.securitymetrics.com/blog/wikid-2fa-enterprise-server-cross-site-scripting | ExploitThird Party Advisory |
Track CVE-2019-17120 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-17120), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.