Lucene search

K
githubGitHub Advisory DatabaseGHSA-GW2Q-CGVQ-9G3V
HistoryMay 17, 2022 - 1:37 a.m.

Roundup Cross-site scripting (XSS) vulnerability

2022-05-1701:37:42
CWE-79
GitHub Advisory Database
github.com
5
roundup
software
xss
vulnerability
cgi/client.py
remote attackers
inject
web script
html
support/issue1

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.003

Percentile

65.1%

Cross-site Scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.

Affected configurations

Vulners
Node
rounduproundupRange<1.4.20
VendorProductVersionCPE
rounduproundup*cpe:2.3:a:roundup:roundup:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.003

Percentile

65.1%