CVE-2010-2491

medium
Published 2010-09-24 · Modified 2024-05-01
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2
4.3
VIR risk
4.3

Description

Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/41585

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/40433

Package impact

EcosystemPackageVulnerableFixed
python PyPIroundup<1.4.141.4.14

Application impact

VendorProductVersionsFixed
roundup-trackerroundup{"endIncluding":"1.4.13"}
roundup-trackerroundup0.1.0
roundup-trackerroundup0.1.1
roundup-trackerroundup0.1.2
roundup-trackerroundup0.1.3
roundup-trackerroundup0.2.0
roundup-trackerroundup0.2.1
roundup-trackerroundup0.2.2
roundup-trackerroundup0.2.3
roundup-trackerroundup0.2.4
roundup-trackerroundup0.2.5
roundup-trackerroundup0.2.6
roundup-trackerroundup0.2.7
roundup-trackerroundup0.2.8
roundup-trackerroundup0.3.0
roundup-trackerroundup0.4.0
roundup-trackerroundup0.4.1
roundup-trackerroundup0.4.2
roundup-trackerroundup0.5
roundup-trackerroundup0.5.0
roundup-trackerroundup0.5.1
roundup-trackerroundup0.5.2
roundup-trackerroundup0.5.3
roundup-trackerroundup0.5.4
roundup-trackerroundup0.5.5
roundup-trackerroundup0.5.6
roundup-trackerroundup0.5.7
roundup-trackerroundup0.5.8
roundup-trackerroundup0.5.9
roundup-trackerroundup0.6.0
roundup-trackerroundup0.6.1
roundup-trackerroundup0.6.2
roundup-trackerroundup0.6.3
roundup-trackerroundup0.6.4
roundup-trackerroundup0.6.5
roundup-trackerroundup0.6.6
roundup-trackerroundup0.6.7
roundup-trackerroundup0.6.8
roundup-trackerroundup0.6.9
roundup-trackerroundup0.6.10
roundup-trackerroundup0.6.11
roundup-trackerroundup0.7.0
roundup-trackerroundup0.7.1
roundup-trackerroundup0.7.2
roundup-trackerroundup0.7.3
roundup-trackerroundup0.7.4
roundup-trackerroundup0.7.5
roundup-trackerroundup0.7.6
roundup-trackerroundup0.7.7
roundup-trackerroundup0.7.8
roundup-trackerroundup0.7.9
roundup-trackerroundup0.7.10
roundup-trackerroundup0.7.11
roundup-trackerroundup0.7.12
roundup-trackerroundup0.8.0
roundup-trackerroundup0.8.1
roundup-trackerroundup0.8.2
roundup-trackerroundup0.8.3
roundup-trackerroundup0.8.4
roundup-trackerroundup0.8.5
roundup-trackerroundup0.8.6
roundup-trackerroundup0.9.0
roundup-trackerroundup1.0
roundup-trackerroundup1.0.1
roundup-trackerroundup1.1.0
roundup-trackerroundup1.1.1
roundup-trackerroundup1.1.2
roundup-trackerroundup1.2.0
roundup-trackerroundup1.2.1
roundup-trackerroundup1.3.0
roundup-trackerroundup1.3.1
roundup-trackerroundup1.3.2
roundup-trackerroundup1.3.3
roundup-trackerroundup1.4.0
roundup-trackerroundup1.4.1
roundup-trackerroundup1.4.2
roundup-trackerroundup1.4.3
roundup-trackerroundup1.4.4
roundup-trackerroundup1.4.5
roundup-trackerroundup1.4.6
roundup-trackerroundup1.4.7
roundup-trackerroundup1.4.8
roundup-trackerroundup1.4.9
roundup-trackerroundup1.4.10
roundup-trackerroundup1.4.11
roundup-trackerroundup1.4.12

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.