GHSA-fh5c-7gmg-xmp6
Dashboard / Vulnerabilities / GHSA-fh5c-7gmg-xmp6
GHSA-fh5c-7gmg-xmp6
Summary: Kallithea cross-site scripting (XSS) vulnerability
Details: Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-1864, https://github.com/msabramo/kallithea, https://github.com/pypa/advisory-database/tree/main/vulns/kallithea/PYSEC-2017-17.yaml, https://kallithea-scm.org/repos/kallithea/changeset/a8f2986afc18c9221bf99f88b06e60ab83c86c55, https://kallithea-scm.org/security/cve-2015-1864.html, https://web.archive.org/web/20200228161446/http://www.securityfocus.com/bid/74184, http://www.openwall.com/lists/oss-security/2015/04/14/12, http://www.securityfocus.com/bid/74184
Affected packages
Package
Name: kallithea
Purl: pkg:pypi/kallithea
Affected ranges
Type: ECOSYSTEM
Events:
