Vulnerabilities
Vulnerable Software
Roundup-Tracker:  >> Roundup  >> 0.5  Security Vulnerabilities
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
CVSS Score
5.4
EPSS Score
0.002
Published
2024-07-17
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
CVSS Score
5.4
EPSS Score
0.002
Published
2024-07-17
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
CVSS Score
5.4
EPSS Score
0.002
Published
2024-07-17
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.
CVSS Score
6.1
EPSS Score
0.005
Published
2020-01-30
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
CVSS Score
4.3
EPSS Score
0.002
Published
2016-04-13
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.
CVSS Score
4.3
EPSS Score
0.004
Published
2014-04-11
Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link.
CVSS Score
4.3
EPSS Score
0.004
Published
2014-04-11
Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.
CVSS Score
4.3
EPSS Score
0.003
Published
2014-04-10
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.
CVSS Score
4.3
EPSS Score
0.006
Published
2010-09-24
Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-site scripting (XSS).
CVSS Score
4.3
EPSS Score
0.01
Published
2008-03-24


Contact Us

Shodan ® - All rights reserved