First published: Wed May 11 2022(Updated: )
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Reviewboard Review Board | =3.0.20 | |
Reviewboard Review Board | =4.0-beta1 | |
Reviewboard Review Board | =4.0-beta2 | |
Reviewboard Review Board | =4.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.