VYPR
Medium severity6.1NVD Advisory· Published Jan 30, 2020· Updated Jun 16, 2026

CVE-2012-6133

CVE-2012-6133

Description

Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
roundupPyPI
< 1.4.201.4.20

Affected products

3
  • cpe:2.3:a:roundup-tracker:roundup:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:roundup-tracker:roundup:*:*:*:*:*:*:*:*range: <1.4.20
    • (no CPE)range: before 1.4.20
  • ghsa-coords
    Range: < 1.4.20

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.