Описание
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| kodi | not-affected | package | ||
| xbmc | removed | package | ||
| xbmc | no-dsa | jessie | package | |
| xbmc | no-dsa | wheezy | package |
Примечания
http://seclists.org/fulldisclosure/2018/Apr/36
https://trac.kodi.tv/ticket/17814
Fixed in v18
EPSS
Связанные уязвимости
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist.
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist.
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist.
EPSS