CVE-2018-0499Cross-site Scripting in Xapian-core

CWE-79Cross-site Scripting10 documents7 sources
Severity
6.1MEDIUMNVD
EPSS
0.4%
top 41.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 2
Latest updateMay 14

Description

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

NVDxapian/xapian-core< 1.4.6
RubyGemsxapian/xapian-core< 1.4.6
debiandebian/xapian-core< xapian-core 1.4.6-1 (bookworm)
Debianxapian/xapian-core< 1.4.6-1+3

Also affects: Ubuntu Linux 17.10, 18.04

Patches

🔴Vulnerability Details

3
OSV
xapian-core Cross-site Scripting vulnerability2022-05-14
GHSA
xapian-core Cross-site Scripting vulnerability2022-05-14
OSV
CVE-2018-0499: A cross-site scripting vulnerability in queryparser/termgenerator_internal2018-07-02

📋Vendor Advisories

3
Ubuntu
Xapian-core vulnerability2018-07-10
Red Hat
xapian-core: Cross-site-scripting in queryparser/termgenerator_internal.cc2018-07-02
Debian
CVE-2018-0499: xapian-core - A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in...2018

💬Community

3
Bugzilla
CVE-2018-0499 xapian-core: Cross-site-scripting in queryparser/termgenerator_internal.cc2018-07-03
Bugzilla
CVE-2018-0499 xapian-core: Cross-site-scripting in queryparser/termgenerator_internal.cc [fedora-all]2018-07-03
Bugzilla
CVE-2018-0499 xapian-core: Cross-site-scripting in queryparser/termgenerator_internal.cc [epel-all]2018-07-03