|
|
| |
|
| |
ReviewBoard: cross-site scripting
| Package(s): | ReviewBoard |
CVE #(s): | CVE-2011-4312
|
| Created: | November 29, 2011 |
Updated: | November 30, 2011 |
| Description: |
From the Red Hat bugzilla:
A cross-site scripting (XSS) flaw was found in the way the commenting system of
the ReviewBoard, a web-based code review tool, sanitized user input (new
comments to be loaded). A remote attacker could provide a specially-crafted
URL, which once visited by valid ReviewBoard user could lead to arbitrary HTML or web script execution in the 'diff viewer' or 'screenshot pages' components. |
| Alerts: |
|
( Log in to post comments)
|
|
|