Описание
The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.
Ссылки
- ExploitIssue TrackingPatchVendor Advisory
- ExploitIssue TrackingMailing ListThird Party Advisory
- Third Party Advisory
- ExploitIssue TrackingPatchVendor Advisory
- ExploitIssue TrackingMailing ListThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
6.1 Medium
CVSS3
Дефекты
Связанные уязвимости
The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.
The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. ...
Deluge Web-UI vulnerable to XSS through a crafted torrent file
EPSS
6.1 Medium
CVSS3