CVE-2012-6132

medium
Published 2022-05-17 · Modified 2024-04-30
CVSS v3
CVSS v2
4.3
VIR risk
4.3

Description

Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
python PyPIroundup<1.4.201.4.20

Application impact

VendorProductVersionsFixed
roundup-trackerroundup{"endIncluding":"1.4.19"}
roundup-trackerroundup1.4.0
roundup-trackerroundup1.4.1
roundup-trackerroundup1.4.2
roundup-trackerroundup1.4.3
roundup-trackerroundup1.4.4
roundup-trackerroundup1.4.5
roundup-trackerroundup1.4.6
roundup-trackerroundup1.4.7
roundup-trackerroundup1.4.8
roundup-trackerroundup1.4.9
roundup-trackerroundup1.4.10
roundup-trackerroundup1.4.11
roundup-trackerroundup1.4.12
roundup-trackerroundup1.4.13
roundup-trackerroundup1.4.14
roundup-trackerroundup1.4.15
roundup-trackerroundup1.4.16
roundup-trackerroundup1.4.17
roundup-trackerroundup1.4.18

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.