Cross-Site Scripting Vulnerability in ViewVC by Tigris.org
CVE-2012-4533

Currently unrated

Key Information:

Vendor

Viewvc

Status
Vendor
CVE Published:
19 November 2012

What is CVE-2012-4533?

A cross-site scripting vulnerability exists in the 'extra' details in the DiffSource._get_row function in lib/viewvc.py in ViewVC versions prior to 1.0.13 and 1.1.16. This flaw allows remote authenticated users with repository commit access to inject arbitrary web scripts or HTML through the 'function name' line, potentially compromising user data or leading to unauthorized actions within the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.