{"id":"CVE-2019-1302","details":"An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'.","aliases":["GHSA-xr8f-59pp-rxxh"],"modified":"2026-07-08T20:05:24.388098Z","published":"2019-09-11T22:15:19.087Z","references":[{"type":"FIX","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dotnet/aspnetcore","events":[{"introduced":"00e08d8c11f4e9649492342c9c613a758efd2e4d"},{"last_affected":"53b0d448a53403ca84bb3dac66dcd20eb375aeaa"}],"database_specific":{"cpe":["cpe:2.3:a:microsoft:asp.net_core:2.1:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:asp.net_core:2.2:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:asp.net_core:3.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.1"},{"last_affected":"2.1"},{"introduced":"2.2"},{"last_affected":"2.2"},{"introduced":"3.0"},{"last_affected":"3.0"}],"source":"CPE_STRING"}}],"versions":["2.1","2.2","3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1302.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}