CVE-2022-24710: Cross-site Scripting in Weblate
Impact Due to improper neutralization, it was possible to perform cross-site scripting via crafted user and language names.
Patches
The issues were fixed in the 4.11 release. The following commits are addressing it:
f6753a1a1c63fade6ad418fbda827c6750ab0bda 9e19a8414337692cc90da2a91c9af5420f2952f1 22d577b1f1e88665a88b4569380148030e0f8389
Workarounds
You can look for crafted user and language names to see if you were affected.
References https://hackerone.com/reports/1486674 https://hackerone.com/reports/1486718 https://hackerone.com/reports/1485226
For more information If you have any questions or comments about this advisory: Open a topic in discussions Email us at care@weblate.org
Other sources
Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24710?
CVE-2022-24710 has medium severity due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2022-24710?
To fix CVE-2022-24710, upgrade to Weblate version 4.11 or later.
What software is affected by CVE-2022-24710?
CVE-2022-24710 affects Weblate versions prior to 4.11.
What type of vulnerability is CVE-2022-24710?
CVE-2022-24710 is a cross-site scripting vulnerability due to improper neutralization.
Where can I find patches for CVE-2022-24710?
Patches for CVE-2022-24710 are included in the Weblate 4.11 release.