Executive brief
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.
Affected products
- PyPI roundup
Junglewise Threat Intelligence
CVE-2010-2491 · Severity: low · CVSS 3.1 · Published 2010-09-24
Technologies: roundup (PyPI). Vendors: PyPI.
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.