Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-02-25T20:50:11

Updated: 2022-02-25T20:50:10

Reserved: 2022-02-10T00:00:00


Link: CVE-2022-24710

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-25T21:15:08.200

Modified: 2022-03-08T15:13:14.510


Link: CVE-2022-24710

JSON object: View

cve-icon Redhat Information

No data.

CWE