MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*
Published Jan 30, 2020
6.1
MEDIUMCVSS 3.1
EPSS 1.56%
Description
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.
Affected products
-
- Version before 1.4.20StatusaffectedConstraints-
- Version
- < 1.4.20
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://issues.roundup-tracker.org/issue2550724 x_refsource_CONFIRMIssue TrackingVendor Advisory
- http://www.openwall.com/lists/oss-security/2012/11/10/2 x_refsource_MISCMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/02/13/8 x_refsource_MISCMailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=722672 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0166 Advisory
- https://github.com/advisories/GHSA-5jq3-8437-x35p Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/roundup/PYSEC-2020-212.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2012-6133
- https://pypi.python.org/pypi/roundup/1.4.20 x_refsource_CONFIRMExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://issues.roundup-tracker.org/issue2550724 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| http://www.openwall.com/lists/oss-security/2012/11/10/2 | x_refsource_MISCMailing ListThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2013/02/13/8 | x_refsource_MISCMailing ListThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=722672 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0166 | Advisory | |
| https://github.com/advisories/GHSA-5jq3-8437-x35p | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/roundup/PYSEC-2020-212.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2012-6133 | ||
| https://pypi.python.org/pypi/roundup/1.4.20 | x_refsource_CONFIRMExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 30, 2020
Updated Aug 6, 2024
Reserved Dec 6, 2012
Link CVE-2012-6133
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-0166 GHSA-5JQ3-8437-X35P Assigner redhat
Published Jan 30, 2020
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2020-0166