Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-11737

Опубликовано: 29 июл. 2017
Источник: debian

Описание

interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rspamdfixed1.7.6-1package
rspamdnot-affectedjessiepackage

Примечания

  • https://github.com/vstakhov/rspamd/issues/1738

  • https://github.com/rspamd/rspamd/pull/1739

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 8 лет назад

interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.

CVSS3: 6.1
nvd
больше 8 лет назад

interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.

CVSS3: 6.1
github
больше 3 лет назад

interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.