Cross-site Scripting in Weblate
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.4epss 0.8%
probabilidad de explotación
0.8%top 48% de las CVE
explotación observada
noninguna fuente lo reporta
Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Productos afectados
WeblateOrg · weblateReferencias
https://github.com/WeblateOrg/weblate/commit/22d577b1f1e88665a88b4569380148030e0f8389https://github.com/WeblateOrg/weblate/commit/9e19a8414337692cc90da2a91c9af5420f2952f1https://github.com/WeblateOrg/weblate/commit/f6753a1a1c63fade6ad418fbda827c6750ab0bdahttps://github.com/WeblateOrg/weblate/security/advisories/GHSA-6jp6-9rf9-gc66