CVE-2014-5027

Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via a query parameter to a diff fragment page.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
reviewboardreview_board
2.0
reviewboardreview_board
2.0:beta1
reviewboardreview_board
2.0:beta2
reviewboardreview_board
2.0:beta3
reviewboardreview_board
2.0:rc1
reviewboardreview_board
2.0:rc2
reviewboardreview_board
2.0:rc3
reviewboardreview_board
2.0.1
reviewboardreview_board
2.0.2
reviewboardreview_board
2.0.3
reviewboardreview_board
1.7.0
reviewboardreview_board
1.7.0.1
reviewboardreview_board
1.7.1
reviewboardreview_board
1.7.2
reviewboardreview_board
1.7.3
reviewboardreview_board
1.7.4
reviewboardreview_board
1.7.5
reviewboardreview_board
1.7.6
reviewboardreview_board
1.7.7
reviewboardreview_board
1.7.8
reviewboardreview_board
1.7.9
reviewboardreview_board
1.7.10
reviewboardreview_board
1.7.11
reviewboardreview_board
1.7.12
reviewboardreview_board
1.7.13
reviewboardreview_board
1.7.14
reviewboardreview_board
1.7.15
reviewboardreview_board
1.7.16
reviewboardreview_board
1.7.17
reviewboardreview_board
1.7.18
reviewboardreview_board
1.7.19
reviewboardreview_board
1.7.20
reviewboardreview_board
1.7.21
reviewboardreview_board
1.7.22
reviewboardreview_board
1.7.23
reviewboardreview_board
1.7.24
reviewboardreview_board
1.7.25
reviewboardreview_board
1.7.26
𝑥
= Vulnerable software versions