CVE-2019-1020005Medium· 5.4▾ SunlitCross-site Scripting in invenio-communities
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
0.7% → 0.9%
A Cross-Site Scripting (XSS) vulnerability was discovered in two Jinja templates in the Invenio-Communities module. The vulnerability allows a user to create a new community and include script element tags inside the description and page fields.
The problem has been patched in v1.0.0a20.
If you have any questions or comments about this advisory:
invenio-communities < 1.0.0a20Upgrade to a patched release:
invenio-communities 1.0.0a20