Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2021-31330
Disclosure Date: May 11, 2022 (last updated October 07, 2023)
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.
0
Attacker Value
Unknown
CVE-2013-4796
Disclosure Date: December 27, 2019 (last updated November 27, 2024)
ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
0
Attacker Value
Unknown
CVE-2013-4411
Disclosure Date: December 03, 2019 (last updated November 27, 2024)
Review Board: URL processing gives unauthorized users access to review lists
0
Attacker Value
Unknown
CVE-2013-4410
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
ReviewBoard: has an access-control problem in REST API
0
Attacker Value
Unknown
CVE-2013-4409
Disclosure Date: November 04, 2019 (last updated November 27, 2024)
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
0
Attacker Value
Unknown
CVE-2014-5028
Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
0
Attacker Value
Unknown
CVE-2014-5027
Disclosure Date: July 25, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via a query parameter to a diff fragment page.
0
Attacker Value
Unknown
CVE-2014-3995
Disclosure Date: June 16, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HTML via a user display name.
0
Attacker Value
Unknown
CVE-2014-3994
Disclosure Date: June 16, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in util/templatetags/djblets_js.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django, as used in Review Board, allows remote attackers to inject arbitrary web script or HTML via a JSON object, as demonstrated by the name field when changing a user name.
0
Attacker Value
Unknown
CVE-2013-4795
Disclosure Date: April 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Submitters list in Review Board 1.6.x before 1.6.18 and 1.7.x before 1.7.12 allows remote attackers to inject arbitrary web script or HTML via a user full name.
0