CVE-2013-4519Cross-site Scripting in Review Board

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 36.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 19
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in Review Board 1.6.x before 1.6.21 and 1.7.x before 1.7.17 allow remote attackers to inject arbitrary web script or HTML via the (1) Branch field or (2) caption of an uploaded file.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDreviewboard/review_board39 versions+38

🔴Vulnerability Details

1
GHSA
GHSA-h799-43v5-pgxw: Multiple cross-site scripting (XSS) vulnerabilities in Review Board 12022-05-17

💬Community

1
Bugzilla
CVE-2013-4519 ReviewBoard: two XSS vulnerabilities2013-11-05