Cross-site scripting invenio-records
Moderate severity
GitHub Reviewed
Published
Jul 15, 2019
in
inveniosoftware/invenio-records
•
Updated Sep 23, 2024
Package
Affected versions
< 1.0.2
= 1.1.0
>= 1.2.0, < 1.2.2
Patched versions
1.0.2
1.1.1
1.2.2
Description
Published to the GitHub Advisory Database
Jul 16, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 23, 2024
Cross-Site Scripting (XSS) vulnerability in administration interface
Impact
A Cross-Site Scripting (XSS) vulnerability was discovered when rendering JSON for a record in the administration interface. The vulnerability could be exploited by e.g. a user who had access to upload a new record, that an admin user would then later view in the admin interface.
Patches
All supported versions of Invenio-Records have been patched. You should upgrade to either v1.0.1, v1.1.1 or v1.2.2
For more information
If you have any questions or comments about this advisory:
References