Junglewise Threat Intelligence

CVE-2012-6133: PYSEC-2020-212 - Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML v

CVE-2012-6133 · Severity: low · CVSS 3.1 · Published 2020-01-30

Technologies: roundup (PyPI). Vendors: PyPI.

Executive brief

Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.

Affected products

  • PyPI roundup

Related threats