CVE-2012-6131

medium
Published 2014-04-11 · Modified 2024-04-30
CVSS v3
CVSS v2
4.3
VIR risk
4.3

Description

Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://pypi.python.org/pypi/roundup/1.4.20

Package impact

EcosystemPackageVulnerableFixed
python PyPIroundup<1.4.201.4.20

Application impact

VendorProductVersionsFixed
roundup-trackerroundup{"endIncluding":"1.4.19"}
roundup-trackerroundup1.4.0
roundup-trackerroundup1.4.1
roundup-trackerroundup1.4.2
roundup-trackerroundup1.4.3
roundup-trackerroundup1.4.4
roundup-trackerroundup1.4.5
roundup-trackerroundup1.4.6
roundup-trackerroundup1.4.7
roundup-trackerroundup1.4.8
roundup-trackerroundup1.4.9
roundup-trackerroundup1.4.10
roundup-trackerroundup1.4.11
roundup-trackerroundup1.4.12
roundup-trackerroundup1.4.13
roundup-trackerroundup1.4.14
roundup-trackerroundup1.4.15
roundup-trackerroundup1.4.16
roundup-trackerroundup1.4.17
roundup-trackerroundup1.4.18

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.