Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10744

Опубликовано: 19 мар. 2019
Источник: redhat
CVSS3: 6.3

Описание

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 5select2Out of support scope
Red Hat Single Sign-On 7rh-sso7-keycloakNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1693166select2: XSS due to missing sanitization when HTML templates are used to display remotely-loaded data.

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 7 лет назад

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.

CVSS3: 6.1
debian
почти 7 лет назад

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich ...

CVSS3: 6.1
github
больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Select2

6.3 Medium

CVSS3