← Vulnerability feed

Vulnerability record · CVE-2019-17120 · published 17 October 2019

CVE-2019-17120: WiKID 2FA Enterprise Server stored and reflected XSS in adm_usrs.jsp

WWikidsystems · 2fa Enterprise Server

WiKID 2FA Enterprise Server through 4.2.0-b2047 is vulnerable to stored and reflected cross-site scripting via the usr parameter of /WiKIDAdmin/adm_usrs.jsp. The reflected payload fires immediately after user creation, and the script is then stored and executed whenever the page is visited. Because this is the administrative user-management interface of an authentication server, script execution there can compromise admin sessions and the 2FA platform itself.

6.1 CVSS 3.1 Medium EPSS 50% · top 1.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp. The usr parameter is vulnerable: the reflected cross-site scripting occurs immediately after the user is created. The malicious script is stored and will be executed whenever /WiKIDAdmin/adm_usrs.jsp is visited.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityPublic exploit code and a very high EPSS score raise the likelihood of attempts, and successful XSS in the 2FA administration console can undermine the authentication platform itself.

What it is

WiKID 2FA Enterprise Server through 4.2.0-b2047 is vulnerable to stored and reflected cross-site scripting via the usr parameter of /WiKIDAdmin/adm_usrs.jsp. The reflected payload fires immediately after user creation, and the script is then stored and executed whenever the page is visited. Because this is the administrative user-management interface of an authentication server, script execution there can compromise admin sessions and the 2FA platform itself.

Impact

An attacker can run arbitrary script or HTML in the browser of an authenticated administrator viewing the user administration page, enabling session theft, credential capture or unauthorized administrative actions. The stored variant means the payload persists and re-executes on later visits without further attacker action.

Attack surface

Reached over the network through the WiKIDAdmin web interface at /WiKIDAdmin/adm_usrs.jsp, with the payload supplied in the usr parameter. The CVSS vector indicates no privileges are required (PR:N) but user interaction is required (UI:R), so an administrator must be induced to create or view the affected user entry.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded. EPSS is high (0.49955, 98.8th percentile) and all three references are tagged Exploit, indicating public proof-of-concept code exists.

What to do

  • Upgrade WiKID 2FA Enterprise Server past 4.2.0-b2047 to a fixed release; the record does not name a fixed version, so confirm with the vendor.
  • If patching is delayed, restrict network access to /WiKIDAdmin/ to trusted management networks or VPN.
  • Encode or reject the usr parameter on input and output, and apply a strict Content-Security-Policy to the admin interface.
  • Require administrators to re-authenticate and rotate sessions and credentials after any suspected exposure.
  • Review the admin interface for other unescaped parameters in the same JSP and related pages.

Detection

  • Search web and proxy logs for requests to /WiKIDAdmin/adm_usrs.jsp containing script tags or event handlers in the usr parameter.
  • Monitor for unexpected script content stored in WiKID user records or rendered on the admin user page.
  • Alert on anomalous admin session activity, such as new admin accounts or configuration changes following visits to adm_usrs.jsp.
  • Correlate outbound requests from administrator browsers to unfamiliar domains shortly after admin page access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-17120 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-17117Wikidsystems 2fa enterprise server sql injection vulnerabilityA SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authenticated user to execute arbitrary…EPSS 1.7%8.8CVE-2019-17118Wikidsystems 2fa enterprise server cross-site request forgery vulnerabilityA CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended ac…EPSS 0.94%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed6.1CVE-2025-66376Zimbra Collaboration Classic UI stored XSS via CSS @import in emailZimbra Collaboration Suite 10 before 10.0.18 and 10.1 before 10.1.13 allows stored cross-site scripting in the Classic UI through CSS @import directi…KEVEPSS 20%analysed6.1CVE-2025-68461Roundcube Webmail XSS via SVG animate tagRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is vulnerable to cross-site scripting through the animate tag in an SVG document. Because the f…KEVEPSS 27%analysed10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed

Source: NIST National Vulnerability Database (record CVE-2019-17120), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.