Vulnerability record · CVE-2019-9834 · published 15 March 2019
CVE-2019-9834: Netdata cross-site scripting vulnerability
Netdata · Netdata
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or to control how the site is rendered to the user. NOTE: the vendor disputes the risk because there is a clear warning next to the button for importing a snapshot
Description
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or to control how the site is rendered to the user. NOTE: the vendor disputes the risk because there is a clear warning next to the button for importing a snapshot
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/netdata/netdata/issues/5800#issuecomment-510986112 | Third Party Advisory |
| https://www.exploit-db.com/exploits/46545 | ExploitThird Party AdvisoryVDB Entry |
| https://www.youtube.com/watch?v=zSG93yX0B8k | ExploitThird Party Advisory |
| https://github.com/netdata/netdata/issues/5800#issuecomment-510986112 | Third Party Advisory |
| https://www.exploit-db.com/exploits/46545 | ExploitThird Party AdvisoryVDB Entry |
| https://www.youtube.com/watch?v=zSG93yX0B8k | ExploitThird Party Advisory |
Track CVE-2019-9834 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-9834), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.