CVE-2019-1020003Medium· 5.4▾ SunlitCross-site scripting invenio-records
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
0.7% → 0.9%
A Cross-Site Scripting (XSS) vulnerability was discovered when rendering JSON for a record in the administration interface. The vulnerability could be exploited by e.g. a user who had access to upload a new record, that an admin user would then later view in the admin interface.
All supported versions of Invenio-Records have been patched. You should upgrade to either v1.0.1, v1.1.1 or v1.2.2
If you have any questions or comments about this advisory:
invenio-records < 1.0.2invenio-records >= 1.1.0, < 1.1.1invenio-records >= 1.2.0, < 1.2.2Upgrade to a patched release:
invenio-records 1.0.2invenio-records 1.1.1invenio-records 1.2.2