PYSEC-2019-112

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/pyarchery/PYSEC-2019-112.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2019-112
Aliases
Published
2019-12-26T23:15:00Z
Modified
2023-11-01T04:50:51.141802Z
Summary
[none]
Details

In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.

References

Affected packages

PyPI / pyarchery

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.0

Affected versions

0.*

0.1
0.2
0.3

1.*

1.0
1.1.0
1.2.0