Описание
Airbnb Knowledge Repo XSS In Comments
Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo prior to 0.9.0 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demonstrated by the post/posts/new_report.kp URI.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-12104
- https://github.com/airbnb/knowledge-repo/issues/254
- https://github.com/airbnb/knowledge-repo/issues/431
- https://github.com/airbnb/knowledge-repo/pull/558
- https://github.com/airbnb/knowledge-repo/commit/f026ad2afea14e0ffc91f1aa0eaedcdc72c63167
- https://github.com/pypa/advisory-database/tree/main/vulns/knowledge-repo/PYSEC-2018-116.yaml
- https://pypi.org/project/knowledge-repo
- https://web.archive.org/web/20200227121013/http://www.securityfocus.com/bid/104487
Пакеты
Наименование
knowledge-repo
pip
Затронутые версииВерсия исправления
< 0.9.0
0.9.0
Связанные уязвимости
CVSS3: 6.1
nvd
больше 7 лет назад
Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demonstrated by the post/posts/new_report.kp URI.