Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0362 | Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic. |
Github GHSA |
GHSA-6jp6-9rf9-gc66 | Cross-site Scripting in Weblate |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T19:00:28.349Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24710
No data.
Status : Modified
Published: 2022-02-25T21:15:08.200
Modified: 2024-11-21T06:50:55.563
Link: CVE-2022-24710
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA