Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Léa Lacroix

Pesquisador deWikimedia Deutschland e.V.
#20728de 53,638
12.2CVSS total
Vulnerabilidades · 2
Média
2
PT-2019-15809
6.1
2019-11-27
Wikimedia · Wikibase Wikidata Query Service Gui · CVE-2019-19327
**Name of the Vulnerable Software and Affected Versions** Wikibase Wikidata Query Service GUI versions prior to 0.3.6-SNAPSHOT **Description** The issue allows HTML injection when reporting the number of results and number of milliseconds in the ui/ResultView.js file. **Recommendations** For versions prior to 0.3.6-SNAPSHOT, update to version 0.3.6-SNAPSHOT or later to resolve the issue.
PT-2019-15810
6.1
2019-11-27
Wikimedia · Wikibase Wikidata Query Service Gui · CVE-2019-19328
**Name of the Vulnerable Software and Affected Versions** Wikibase Wikidata Query Service GUI versions prior to 0.3.6-SNAPSHOT **Description** The issue allows HTML injection in tooltips for entities, specifically affecting the ui/editor/tooltip/Rdf.js component. This could potentially lead to malicious HTML being injected into tooltips. **Recommendations** For versions prior to 0.3.6-SNAPSHOT, update to version 0.3.6-SNAPSHOT or later to resolve the issue.