Security Advisory

CVE-2011-0728

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2011-03-29 18:00:00
Last updated 2024-08-06 22:05:53
Assigner canonical
State PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.