CVE-2011-2711 PUBLISHED CVSS 8.5 HIGH

Cross-site scripting (XSS) vulnerability in the print_fileinfo function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the filename associated with the rename hint.

EPSS 0.37% · 58.7th percentile

Risk Scores

CVSS v4.0
8.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.37%
58.7th percentile

Affected Products

VendorProductVersions
lars_hjemlicgit0.9.0.1, 0, 0.1
n/an/an/a

Timeline

References

Open in Interactive Console →