Back to Database
Status published
Medium
CVE-2012-6131
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-6131
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=722672
- https://pypi.python.org/pypi/roundup/1.4.20
- http://www.openwall.com/lists/oss-security/2013/02/13/8
- http://www.openwall.com/lists/oss-security/2012/11/10/2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84190
- http://issues.roundup-tracker.org/issue2550711
More from roundup-tracker
View All →CVE-2025-53865
In Roundup before 2.5.0, XSS can occur via interaction between...
Medium
6.4
CVE-2014-6276
schema.py in Roundup before 1.5.1 does not properly limit attributes...
Medium
4.3
CVE-2012-6132
Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote...
Medium
4.3
CVE-2012-6130
Cross-site scripting (XSS) vulnerability in the history display in Roundup...
Medium
4.3
CVE-2010-2491
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14...
Medium
4.3
Affected Vendor
roundup-tracker
View all reports →Affected Software
roundup
Vulnerable Versions:
0, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9, 1.4.10, 1.4.11, 1.4.12, 1.4.13, 1.4.14, 1.4.15, 1.4.16, 1.4.17, 1.4.18
Timeline
Official Publish:
April 11th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.