4.3
CVSSv2

CVE-2017-15612

Published: 19/10/2017 Updated: 07/11/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.

Vulnerable Product Search on Vulmon Subscribe to Product

mistune project mistune 0.7.4

Vendor Advisories

Debian Bug report logs - #879098 mistune: CVE-2017-15612: cross-site scripting vulnerablity Package: src:mistune; Maintainer for src:mistune is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 19 Oct 2017 11:48:01 UTC Severity: ...