MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Review Board 1.6.x before 1.6.21 and 1.7.x before 1.7.17 allow remote attackers to inject arbitrary web script or HTML via the (1) Branch field or (2) caption of an uploaded file
Published Nov 15, 2013
4.3
MEDIUMCVSS 2.0
EPSS 2.02%
Description
Multiple cross-site scripting (XSS) vulnerabilities in Review Board 1.6.x before 1.6.21 and 1.7.x before 1.7.17 allow remote attackers to inject arbitrary web script or HTML via the (1) Branch field or (2) caption of an uploaded file.
Affected products
No data.
OR
- 1.6
- 1.6
- 1.6
- 1.6
- 1.6
- 1.6.1
- 1.6.2
- 1.6.3
- 1.6.4
- 1.6.5
- 1.6.6
- 1.6.7
- 1.6.8
- 1.6.9
- 1.6.10
- 1.6.11
- 1.6.12
- 1.6.13
- 1.6.14
- 1.6.15
- 1.6.16
- 1.6.17
- 1.6.18
- 1.6.19
- 1.6.20
- 1.7.0
- 1.7.0.1
- 1.7.1
- 1.7.2
- 1.7.3
- 1.7.4
- 1.7.5
- 1.7.6
- 1.7.7
- 1.7.8
- 1.7.9
- 1.7.10
- 1.7.11
- 1.7.12
- 1.7.13
- 1.7.14
- 1.7.15
- 1.7.16
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://osvdb.org/99512 vdb-entryx_refsource_OSVDB
- http://osvdb.org/99513 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/55623 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.reviewboard.org/docs/releasenotes/reviewboard/1.6.21 x_refsource_CONFIRMVendor Advisory
- http://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.17 x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/63601 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-4378 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88620 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/99512 | vdb-entryx_refsource_OSVDB | |
| http://osvdb.org/99513 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/55623 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.reviewboard.org/docs/releasenotes/reviewboard/1.6.21 | x_refsource_CONFIRMVendor Advisory | |
| http://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.17 | x_refsource_CONFIRMVendor Advisory | |
| http://www.securityfocus.com/bid/63601 | vdb-entryx_refsource_BID | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-4378 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/88620 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 15, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4519
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-4378 Assigner redhat
Published Nov 15, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-4378