CVE-2013-4519

EUVD-2013-4378
Multiple cross-site scripting (XSS) vulnerabilities in Review Board 1.6.x before 1.6.21 and 1.7.x before 1.7.17 allow remote attackers to inject arbitrary web script or HTML via the (1) Branch field or (2) caption of an uploaded file.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
reviewboardreview_board
1.6
reviewboardreview_board
1.6:beta1
reviewboardreview_board
1.6:beta2
reviewboardreview_board
1.6:rc1
reviewboardreview_board
1.6:rc2
reviewboardreview_board
1.6.1
reviewboardreview_board
1.6.2
reviewboardreview_board
1.6.3
reviewboardreview_board
1.6.4
reviewboardreview_board
1.6.5
reviewboardreview_board
1.6.6
reviewboardreview_board
1.6.7
reviewboardreview_board
1.6.8
reviewboardreview_board
1.6.9
reviewboardreview_board
1.6.10
reviewboardreview_board
1.6.11
reviewboardreview_board
1.6.12
reviewboardreview_board
1.6.13
reviewboardreview_board
1.6.14
reviewboardreview_board
1.6.15
reviewboardreview_board
1.6.16
reviewboardreview_board
1.6.17
reviewboardreview_board
1.6.18
reviewboardreview_board
1.6.19
reviewboardreview_board
1.6.20
reviewboardreview_board
1.7.0
reviewboardreview_board
1.7.0.1
reviewboardreview_board
1.7.1
reviewboardreview_board
1.7.2
reviewboardreview_board
1.7.3
reviewboardreview_board
1.7.4
reviewboardreview_board
1.7.5
reviewboardreview_board
1.7.6
reviewboardreview_board
1.7.7
reviewboardreview_board
1.7.8
reviewboardreview_board
1.7.9
reviewboardreview_board
1.7.10
reviewboardreview_board
1.7.11
reviewboardreview_board
1.7.12
reviewboardreview_board
1.7.13
reviewboardreview_board
1.7.14
reviewboardreview_board
1.7.15
reviewboardreview_board
1.7.16
𝑥
= Vulnerable software versions