The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.
{ "binaries": [ { "binary_name": "deluge", "binary_version": "1.3.12-1ubuntu1" }, { "binary_name": "deluge-common", "binary_version": "1.3.12-1ubuntu1" }, { "binary_name": "deluge-console", "binary_version": "1.3.12-1ubuntu1" }, { "binary_name": "deluge-gtk", "binary_version": "1.3.12-1ubuntu1" }, { "binary_name": "deluge-torrent", "binary_version": "1.3.12-1ubuntu1" }, { "binary_name": "deluge-web", "binary_version": "1.3.12-1ubuntu1" }, { "binary_name": "deluge-webui", "binary_version": "1.3.12-1ubuntu1" }, { "binary_name": "deluged", "binary_version": "1.3.12-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "deluge", "binary_version": "1.3.15-2" }, { "binary_name": "deluge-common", "binary_version": "1.3.15-2" }, { "binary_name": "deluge-console", "binary_version": "1.3.15-2" }, { "binary_name": "deluge-gtk", "binary_version": "1.3.15-2" }, { "binary_name": "deluge-torrent", "binary_version": "1.3.15-2" }, { "binary_name": "deluge-web", "binary_version": "1.3.15-2" }, { "binary_name": "deluge-webui", "binary_version": "1.3.15-2" }, { "binary_name": "deluged", "binary_version": "1.3.15-2" } ] }
{ "binaries": [ { "binary_name": "deluge", "binary_version": "2.0.3-2" }, { "binary_name": "deluge-common", "binary_version": "2.0.3-2" }, { "binary_name": "deluge-console", "binary_version": "2.0.3-2" }, { "binary_name": "deluge-gtk", "binary_version": "2.0.3-2" }, { "binary_name": "deluge-web", "binary_version": "2.0.3-2" }, { "binary_name": "deluged", "binary_version": "2.0.3-2" } ] }
{ "binaries": [ { "binary_name": "deluge", "binary_version": "2.0.3-3.1" }, { "binary_name": "deluge-common", "binary_version": "2.0.3-3.1" }, { "binary_name": "deluge-console", "binary_version": "2.0.3-3.1" }, { "binary_name": "deluge-gtk", "binary_version": "2.0.3-3.1" }, { "binary_name": "deluge-web", "binary_version": "2.0.3-3.1" }, { "binary_name": "deluged", "binary_version": "2.0.3-3.1" } ] }
{ "binaries": [ { "binary_name": "deluge", "binary_version": "2.1.2~dev0+20240121-1" }, { "binary_name": "deluge-common", "binary_version": "2.1.2~dev0+20240121-1" }, { "binary_name": "deluge-console", "binary_version": "2.1.2~dev0+20240121-1" }, { "binary_name": "deluge-gtk", "binary_version": "2.1.2~dev0+20240121-1" }, { "binary_name": "deluge-web", "binary_version": "2.1.2~dev0+20240121-1" }, { "binary_name": "deluged", "binary_version": "2.1.2~dev0+20240121-1" } ] }