ALT-PU-2017-2369-1
Package qbittorrent updated to version 3.3.16-alt0.M80P.1 for branch p8 in task 190104.
Closed vulnerabilities
Published: 2017-03-06
Modified: 2025-04-20
Modified: 2025-04-20
CVE-2017-6503
WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.
Severity: MEDIUM (4.3)
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Severity: MEDIUM (6.1)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References:
- http://www.securityfocus.com/bid/96758
- https://github.com/qbittorrent/qBittorrent/commit/6ca3e4f094da0a0017cb2d483ec1db6176bb0b16
- https://www.qbittorrent.org/news.php
- http://www.securityfocus.com/bid/96758
- https://github.com/qbittorrent/qBittorrent/commit/6ca3e4f094da0a0017cb2d483ec1db6176bb0b16
- https://www.qbittorrent.org/news.php
Published: 2017-03-06
Modified: 2025-04-20
Modified: 2025-04-20
CVE-2017-6504
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
Severity: MEDIUM (4.3)
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Severity: MEDIUM (6.1)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References: