PT-2011-1048 · Viewvc · Viewvc

·

CVE-2012-4533

·

Published

2011-05-23

·

Updated

2023-02-13

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ViewVC versions 1.0.x through 1.0.12 ViewVC versions 1.1.x through 1.1.15
Description The issue allows remote authenticated users with repository commit access to inject arbitrary web script or HTML. This can be achieved via the function name line in the extra details in the DiffSource. get row function in lib/viewvc.py. The vulnerability may lead to a breach of protected information and can be exploited remotely.
Recommendations For ViewVC versions 1.0.x through 1.0.12, update to version 1.0.13 or later. For ViewVC versions 1.1.x through 1.1.15, update to version 1.1.16 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03044
CVE-2012-4533
DSA-2563-1

Affected Products

Viewvc