CVE-2012-4533: XSS
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource.getrow function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbitrary web script or HTML via the "function name" line.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4533?
CVE-2012-4533 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS).
How do I fix CVE-2012-4533?
To fix CVE-2012-4533, upgrade to ViewVC version 1.0.13 or 1.1.16 or later.
Who is affected by CVE-2012-4533?
CVE-2012-4533 affects authenticated users with commit access in ViewVC version 1.0.x before 1.0.13 and 1.1.x before 1.1.16.
What type of attack does CVE-2012-4533 enable?
CVE-2012-4533 enables an attacker to inject arbitrary web scripts or HTML, potentially leading to exploitation through cross-site scripting.
Can CVE-2012-4533 affect Debian Linux systems?
Yes, CVE-2012-4533 can affect Debian Linux systems running vulnerable versions of ViewVC.