Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c8p-qhch-qhx6

Опубликовано: 27 авг. 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Deluge Web-UI vulnerable to XSS through a crafted torrent file

The Deluge Web-UI is vulnerable to cross-site scripting through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

Пакеты

Наименование

deluge

pip
Затронутые версииВерсия исправления

< 2.1.0

2.1.0

EPSS

Процентиль: 70%
0.00632
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 3 лет назад

The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

CVSS3: 6.1
nvd
больше 3 лет назад

The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

CVSS3: 6.1
debian
больше 3 лет назад

The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. ...

EPSS

Процентиль: 70%
0.00632
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79