Lucene search

K
githubGitHub Advisory DatabaseGHSA-W7RQ-8F2G-JVQR
HistoryMay 17, 2022 - 3:50 a.m.

Djiblets Cross-site scripting Vulnerability via JSON Objects

2022-05-1703:50:02
CWE-79
GitHub Advisory Database
github.com
10
cross-site scripting
json object
remote attackers
web script
html
user name
review board
vulnerability
djblets
django

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

61.0%

A cross-site scripting (XSS) vulnerability in util/templatetags/djblets_js.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django, as used in Review Board, allows remote attackers to inject arbitrary web script or HTML via a JSON object, as demonstrated by the name field when changing a user name.

Affected configurations

Vulners
Node
reviewboarddjbletsRange0.80.8.3
OR
reviewboarddjbletsRange<0.7.30
VendorProductVersionCPE
reviewboarddjblets*cpe:2.3:a:reviewboard:djblets:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

61.0%