PT-2022-16820 · Weblate · Weblate

Nijel

·

Published

2022-02-25

·

Updated

2024-06-15

·

CVE-2022-24710

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 4.11
Description Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization, it is possible to perform cross-site scripting via these fields.
Recommendations For versions prior to 4.11, users are advised to add their own neutralize logic to prevent cross-site scripting attacks. As a temporary workaround, consider adding input validation for user name and language fields until a patch is available. For users who can upgrade, the issues were fixed in the 4.11 release.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-WEBLATE-2022-24710
CVE-2022-24710
GHSA-6JP6-9RF9-GC66
OPENSUSE-SU-2024:11887-1
PYSEC-2022-35

Affected Products

Weblate