First published: Tue Aug 23 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Marcus Schafer Kiwi | <=3.74.1 | |
Novell Suse Studio Onsite | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2644 is classified as a medium-severity vulnerability due to its cross-site scripting (XSS) nature.
To fix CVE-2011-2644, upgrade Kiwi to version 3.74.2 or later and ensure SUSE Studio is updated to version 1.1.4 or later.
CVE-2011-2644 can facilitate cross-site scripting attacks, allowing remote attackers to inject arbitrary web scripts or HTML.
CVE-2011-2644 affects Kiwi versions before 3.74.2 and SUSE Studio Onsite version 1.1.
Yes, CVE-2011-2644 has been identified as having potential exploitation vectors related to RPM info display.