Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-24710

Опубликовано: 25 фев. 2022
Источник: debian

Описание

Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
weblateitppackage

Связанные уязвимости

CVSS3: 5.4
nvd
почти 4 года назад

Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic.

CVSS3: 5.4
github
почти 4 года назад

Cross-site Scripting in Weblate