Cross-site Scripting (XSS) Affecting kallithea package, versions [,0.2.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.18% (55th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-KALLITHEA-40692
  • published9 Nov 2017
  • disclosed11 Apr 2015
  • creditAndrew Shadura

Introduced: 11 Apr 2015

CVE-2015-1864  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade kallithea to version 0.2.1 or higher.

Overview

kallithea is a fast and powerful management tool for Mercurial and Git with a built in push/pull server, full text search and code-review.

Affected Versions of this package are vulnerable to Cross-site Scripting (XSS) attacks. Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description.

Details

<>

You can read more about Cross-site Scripting (XSS) on our blog.

CVSS Scores

version 3.1