CVE-2013-2209Medium· 6.1▾ SunlitReview Board Cross-site scripting (XSS) vulnerability in the reviews dropdown
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.2%
2.2% → 2.2%
Cross-site scripting (XSS) vulnerability in the auto-complete widget in htdocs/media/rb/js/reviews.js in Review Board 1.6.x before 1.6.17 and 1.7.x before 1.7.10 allows remote attackers to inject arbitrary web script or HTML via a full name.
reviewboard >= 1.6, < 1.6.17reviewboard >= 1.7, < 1.7.10Upgrade to a patched release:
reviewboard 1.6.17reviewboard 1.7.10