CVE-2022-24710: Cross-site Scripting in Weblate

Published Feb 25, 2022
·
Updated

Impact Due to improper neutralization, it was possible to perform cross-site scripting via crafted user and language names.

Patches

The issues were fixed in the 4.11 release. The following commits are addressing it:

f6753a1a1c63fade6ad418fbda827c6750ab0bda 9e19a8414337692cc90da2a91c9af5420f2952f1 22d577b1f1e88665a88b4569380148030e0f8389

Workarounds

You can look for crafted user and language names to see if you were affected.

References https://hackerone.com/reports/1486674 https://hackerone.com/reports/1486718 https://hackerone.com/reports/1485226

For more information If you have any questions or comments about this advisory: Open a topic in discussions Email us at care@weblate.org

Other sources

Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic.

Affected Software

2 affected componentsFixes available
pip/Weblate<4.11
4.11
Weblate weblate<4.11

Event History

Feb 25, 2022
CVE Published
via MITRE·08:50 PM
Data Sourced
via MITRE·08:50 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·10:18 PM

Frequently Asked Questions

1

What is the severity of CVE-2022-24710?

CVE-2022-24710 has medium severity due to its potential to allow cross-site scripting attacks.

2

How do I fix CVE-2022-24710?

To fix CVE-2022-24710, upgrade to Weblate version 4.11 or later.

3

What software is affected by CVE-2022-24710?

CVE-2022-24710 affects Weblate versions prior to 4.11.

4

What type of vulnerability is CVE-2022-24710?

CVE-2022-24710 is a cross-site scripting vulnerability due to improper neutralization.

5

Where can I find patches for CVE-2022-24710?

Patches for CVE-2022-24710 are included in the Weblate 4.11 release.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203