Опубликовано: 16 июл. 2019
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 5.4
Описание
Cross-site Scripting in invenio-communities
Cross-Site Scripting (XSS) vulnerability in Jinja templates
Impact
A Cross-Site Scripting (XSS) vulnerability was discovered in two Jinja templates in the Invenio-Communities module. The vulnerability allows a user to create a new community and include script element tags inside the description and page fields.
Patches
The problem has been patched in v1.0.0a20.
For more information
If you have any questions or comments about this advisory:
- Email us at info@inveniosoftware.org
Пакеты
Наименование
invenio-communities
pip
Затронутые версииВерсия исправления
<= 1.0.0a19
1.0.0a20