Описание
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 1.4.4-2ubuntu0.1 |
| bionic | released | 1.4.5-1ubuntu0.1 |
| devel | not-affected | 1.4.6-1 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra/bionic | released | 1.4.5-1ubuntu0.1 |
| esm-infra/xenial | not-affected | code not present |
| precise/esm | not-affected | code not present |
| trusty | not-affected | code not present |
| trusty/esm | not-affected | code not present |
| upstream | released | 1.4.6-1 |
Показывать по
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
A cross-site scripting vulnerability in queryparser/termgenerator_inte ...
Уязвимость функции Xapian::MSet::snippet() библиотеки для полнотекстового поиска Xapian (xapian-core), позволяющая нарушителю осуществить межсайтовое выполнение сценариев
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3