REDHAT-BUG-754126: XSS
A cross-site scripting (XSS) flaw was found in the way the commenting system of the ReviewBoard, a web-based code review tool, sanitized user input (new comments to be loaded). A remote attacker could provide a specially-crafted URL, which once visited by valid ReviewBoard user could lead to arbitrary HTML or web script execution in the 'diff viewer' or 'screenshot pages' components.
References: [1] http://www.reviewboard.org/news/ [2] http://www.reviewboard.org/docs/releasenotes/dev/reviewboard/1.6.3/
Relevant upstream patch: [3] https://github.com/reviewboard/reviewboard/commit/7a0a9d94555502278534dedcf2d75e9fccce8c3d
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-754126?
The severity of REDHAT-BUG-754126 is considered medium due to the potential for remote exploitation via cross-site scripting.
How do I fix REDHAT-BUG-754126?
To fix REDHAT-BUG-754126, ensure that you are using the latest version of ReviewBoard which addresses this XSS vulnerability.
Who is affected by REDHAT-BUG-754126?
Users of ReviewBoard who utilize the commenting system are affected by REDHAT-BUG-754126.
What type of vulnerability is REDHAT-BUG-754126?
REDHAT-BUG-754126 is a cross-site scripting (XSS) vulnerability that can allow attackers to inject malicious scripts.
Can REDHAT-BUG-754126 be exploited remotely?
Yes, REDHAT-BUG-754126 can be exploited remotely by attackers through specially-crafted URLs.