Cross-site scripting (XSS) vulnerability in the auto-complete widget in htdocs/media/rb/js/reviews.js in Review Board 1.6.x before 1.6.17 and 1.7.x before 1.7.10 allows remote attackers to inject arbitrary web script or HTML via a full name.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| reviewboard(PyPI) | 1.6 | 1.6.17 | N/A |
| reviewboard(PyPI) | 1.7 | 1.7.10 | N/A |
CVSS Metrics