cbcvebase.
CVE-2012-4533
published 2012-11-19

CVE-2012-4533: Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x…

PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.08%
86.4th percentile
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbitrary web script or HTML via the "function name" line.

Affected

5 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
viewvcviewvc>= 0 < 1.1.5-1.41.1.5-1.4
viewvcviewvc>= 1.0.0 < 1.0.131.0.13
viewvcviewvc>= 1.1.0 < 1.1.161.1.16

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.