CVE-2013-2209Cross-site Scripting in Review Board

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 38.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 31
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in the auto-complete widget in htdocs/media/rb/js/reviews.js in Review Board 1.6.x before 1.6.17 and 1.7.x before 1.7.10 allows remote attackers to inject arbitrary web script or HTML via a full name.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

PyPIreviewboard/reviewboard1.61.6.17+1
NVDreviewboard/review_board28 versions+27

Patches

🔴Vulnerability Details

2
GHSA
Review Board Cross-site scripting (XSS) vulnerability in the reviews dropdown2022-05-17
OSV
Review Board Cross-site scripting (XSS) vulnerability in the reviews dropdown2022-05-17

💬Community

3
Bugzilla
CVE-2013-2209 ReviewBoard: Stored XSS due improper sanitization of user's full name in the reviews dropdown2013-06-24
Bugzilla
CVE-2013-2209 ReviewBoard: Stored XSS due improper sanitization of user's full name in the reviews dropdown [fedora-all]2013-06-24
Bugzilla
CVE-2013-2209 ReviewBoard: Stored XSS due improper sanitization of user's full name in the reviews dropdown [epel-6]2013-06-24