PYSEC-2018-116

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/knowledge-repo/PYSEC-2018-116.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2018-116
Aliases
Published
2018-06-17T20:29:00Z
Modified
2026-06-10T17:01:49.071479008Z
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demonstrated by the post/posts/new_report.kp URI.

References

Affected packages

PyPI / knowledge-repo

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.5

Affected versions

0.*
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.6.10
0.6.11
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/knowledge-repo/PYSEC-2018-116.yaml"