Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2021-31330

Disclosure Date: May 11, 2022 (last updated October 07, 2023)
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.
Attacker Value
Unknown

CVE-2013-4796

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
Attacker Value
Unknown

CVE-2013-4411

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
Review Board: URL processing gives unauthorized users access to review lists
Attacker Value
Unknown

CVE-2013-4410

Disclosure Date: December 02, 2019 (last updated November 27, 2024)
ReviewBoard: has an access-control problem in REST API
Attacker Value
Unknown

CVE-2013-4409

Disclosure Date: November 04, 2019 (last updated November 27, 2024)
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
Attacker Value
Unknown

CVE-2014-5028

Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
0
Attacker Value
Unknown

CVE-2014-5027

Disclosure Date: July 25, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via a query parameter to a diff fragment page.
0
Attacker Value
Unknown

CVE-2014-3995

Disclosure Date: June 16, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HTML via a user display name.
0
Attacker Value
Unknown

CVE-2014-3994

Disclosure Date: June 16, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in util/templatetags/djblets_js.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django, as used in Review Board, allows remote attackers to inject arbitrary web script or HTML via a JSON object, as demonstrated by the name field when changing a user name.
0
Attacker Value
Unknown

CVE-2013-4795

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Submitters list in Review Board 1.6.x before 1.6.18 and 1.7.x before 1.7.12 allows remote attackers to inject arbitrary web script or HTML via a user full name.
0