PT-2019-11619 · Invenio · Invenio-Records

Published

2019-07-16

·

Updated

2019-08-01

·

CVE-2019-1020003

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Invenio-Records versions prior to 1.2.2
Description: A Cross-Site Scripting (XSS) issue was found in the administration interface when rendering JSON for a record. This could be exploited by a user with access to upload a new record that an admin user would later view.
Recommendations: For versions prior to 1.0.1, upgrade to v1.0.1. For versions prior to 1.1.1, upgrade to v1.1.1. For versions prior to 1.2.2, upgrade to v1.2.2.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1020003
GHSA-VXH3-MVV7-265J
PYSEC-2019-27

Affected Products

Invenio-Records