dpup fittr-flickr EXIF Preview easy-exif.js cross site scripting
Published Jan 13, 2023
6.1
MEDIUMCVSS 3.1
EPSS 0.54%
Description
A vulnerability, which was classified as problematic, has been found in dpup fittr-flickr. This issue affects some unknown processing of the file fittr-flickr/features/easy-exif.js of the component EXIF Preview Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier of the patch is 08875dd8a2e5d0d16568bb0d67cb4328062fccde. It is recommended to apply a patch to fix this issue. The identifier VDB-218297 was assigned to this vulnerability.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Dpup | Fittr-Flickr | n/a |
|
- < 2009-11-03
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://github.com/dpup/fittr-flickr/commit/08875dd8a2e5d0d16568bb0d67cb4328062fccde patchThird Party Advisory
- https://vuldb.com/?ctiid.218297 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.218297 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/dpup/fittr-flickr/commit/08875dd8a2e5d0d16568bb0d67cb4328062fccde | patchThird Party Advisory | |
| https://vuldb.com/?ctiid.218297 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.218297 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.