Skip to content

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Weblate

Moderate
nijel published GHSA-6jp6-9rf9-gc66 Feb 25, 2022

Package

pip Weblate (pip)

Affected versions

<4.11

Patched versions

4.11

Description

Impact

Due to improper neutralization, it was possible to perform cross-site scripting via crafted user and language names.

Patches

The issues were fixed in the 4.11 release. The following commits are addressing it:

Workarounds

You can look for crafted user and language names to see if you were affected.

References

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2022-24710

Weaknesses