Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4807

Опубликовано: 11 янв. 2017
Источник: debian

Описание

Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
web2pyremovedpackage
web2pyignoredjessiepackage
web2pyno-dsawheezypackage

Примечания

  • https://github.com/web2py/web2py/issues/1585

  • https://github.com/web2py/web2py/commit/51c3b633fe7ad647bc3013e899c1e3a910362dd1

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 9 лет назад

Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).

CVSS3: 4.8
nvd
около 9 лет назад

Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).

CVSS3: 4.8
github
больше 3 лет назад

Web2py Reflected XSS vulnerability