Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-24710

Опубликовано: 25 фев. 2022
Источник: nvd
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*
Версия до 4.11 (исключая)

EPSS

Процентиль: 54%
0.00311
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
debian
почти 4 года назад

Weblate is a copyleft software web-based continuous localization syste ...

CVSS3: 5.4
github
почти 4 года назад

Cross-site Scripting in Weblate

EPSS

Процентиль: 54%
0.00311
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79