Loading
A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could abuse this flaw to trick an authenticated user into clicking a specially crafted link which can execute arbitrary code when viewed in a browser.
Use CWE-79, Redhat vendor hub and Enterprise Linux product page to widen CVE-2019-10221 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-28369, CVE-2026-28368 and CVE-2026-35091 for nearby disclosures in the same product family.