CVE-2018-1000998

FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited impact--CVSweb is anonymous & read-only. It might impact other sites on same domain. This attack appears to be exploitable via victim must load specially crafted url. This vulnerability appears to have been fixed in 3.x.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
freebsdcvsweb
2.0.4 ≤
𝑥
≤ 2.0.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cvsweb
sid
3:3.0.6-8.1
fixed
trixie
3:3.0.6-8.1
fixed
bookworm
3:3.0.6-8.1
fixed
bullseye
3:3.0.6-8.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cvsweb
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne