The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.
{
"binaries": [
{
"binary_name": "deluge",
"binary_version": "1.3.12-1ubuntu1"
},
{
"binary_name": "deluge-common",
"binary_version": "1.3.12-1ubuntu1"
},
{
"binary_name": "deluge-console",
"binary_version": "1.3.12-1ubuntu1"
},
{
"binary_name": "deluge-gtk",
"binary_version": "1.3.12-1ubuntu1"
},
{
"binary_name": "deluge-torrent",
"binary_version": "1.3.12-1ubuntu1"
},
{
"binary_name": "deluge-web",
"binary_version": "1.3.12-1ubuntu1"
},
{
"binary_name": "deluge-webui",
"binary_version": "1.3.12-1ubuntu1"
},
{
"binary_name": "deluged",
"binary_version": "1.3.12-1ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "deluge",
"binary_version": "1.3.15-2"
},
{
"binary_name": "deluge-common",
"binary_version": "1.3.15-2"
},
{
"binary_name": "deluge-console",
"binary_version": "1.3.15-2"
},
{
"binary_name": "deluge-gtk",
"binary_version": "1.3.15-2"
},
{
"binary_name": "deluge-torrent",
"binary_version": "1.3.15-2"
},
{
"binary_name": "deluge-web",
"binary_version": "1.3.15-2"
},
{
"binary_name": "deluge-webui",
"binary_version": "1.3.15-2"
},
{
"binary_name": "deluged",
"binary_version": "1.3.15-2"
}
]
}
{
"binaries": [
{
"binary_name": "deluge",
"binary_version": "2.0.3-2"
},
{
"binary_name": "deluge-common",
"binary_version": "2.0.3-2"
},
{
"binary_name": "deluge-console",
"binary_version": "2.0.3-2"
},
{
"binary_name": "deluge-gtk",
"binary_version": "2.0.3-2"
},
{
"binary_name": "deluge-web",
"binary_version": "2.0.3-2"
},
{
"binary_name": "deluged",
"binary_version": "2.0.3-2"
}
]
}
{
"binaries": [
{
"binary_name": "deluge",
"binary_version": "2.0.3-3.1"
},
{
"binary_name": "deluge-common",
"binary_version": "2.0.3-3.1"
},
{
"binary_name": "deluge-console",
"binary_version": "2.0.3-3.1"
},
{
"binary_name": "deluge-gtk",
"binary_version": "2.0.3-3.1"
},
{
"binary_name": "deluge-web",
"binary_version": "2.0.3-3.1"
},
{
"binary_name": "deluged",
"binary_version": "2.0.3-3.1"
}
]
}
{
"binaries": [
{
"binary_name": "deluge",
"binary_version": "2.1.2~dev0+20240121-1"
},
{
"binary_name": "deluge-common",
"binary_version": "2.1.2~dev0+20240121-1"
},
{
"binary_name": "deluge-console",
"binary_version": "2.1.2~dev0+20240121-1"
},
{
"binary_name": "deluge-gtk",
"binary_version": "2.1.2~dev0+20240121-1"
},
{
"binary_name": "deluge-web",
"binary_version": "2.1.2~dev0+20240121-1"
},
{
"binary_name": "deluged",
"binary_version": "2.1.2~dev0+20240121-1"
}
]
}