VulnerabilityModified
CVE-2013-4519
Multiple cross-site scripting (XSS) vulnerabilities in Review Board 1.6.x before 1.6.21 and 1.7.x before 1.7.17 allow remote attackers to inject arbitrary web script or HTML via the (1) Branch field or (2) caption of an uploaded file.
MEDIUM 4.3EPSS 2.02%
Does this matter?
Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Review Board 1.6.x before 1.6.21 and 1.7.x before 1.7.17 allow remote attackers to inject arbitrary web script or HTML via the (1) Branch field or (2) caption of an uploaded file.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.02% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- reviewboard/review board
- Source
- secalert@redhat.com
References
- http://osvdb.org/99512
- http://osvdb.org/99513
- http://secunia.com/advisories/55623Vendor Advisory
- http://www.reviewboard.org/docs/releasenotes/reviewboard/1.6.21Vendor Advisory
- http://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.17Vendor Advisory
- http://www.securityfocus.com/bid/63601
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88620
- http://osvdb.org/99512
- http://osvdb.org/99513
- http://secunia.com/advisories/55623Vendor Advisory
- http://www.reviewboard.org/docs/releasenotes/reviewboard/1.6.21Vendor Advisory
- http://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.17Vendor Advisory
- http://www.securityfocus.com/bid/63601
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88620
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.