Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 4.6
CVSS3: 4.8
Описание
Cabot Cross Site Scripting (XSS) vulnerability via Address column
Cross Site Scripting (XSS) vulnerability in Arachnys Cabot up to and including 0.11.12 can be exploited via the Address column.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-25449
- https://github.com/arachnys/cabot/commit/18708572cb0ed143842409419eada91160413973
- https://github.com/pypa/advisory-database/tree/main/vulns/cabot/PYSEC-2020-226.yaml
- https://itsmeanonartist.tech/blogs/blog2.html
- https://packetstormsecurity.com/files/159070/Cabot-0.11.12-Cross-Site-Scripting.html
- https://www.exploit-db.com/exploits/48791
- https://www.exploitalert.com/view-details.html?id=36106
Пакеты
Наименование
cabot
pip
Затронутые версииВерсия исправления
<= 0.11.12
Отсутствует
Связанные уязвимости
CVSS3: 4.8
nvd
около 5 лет назад
Cross Site Scripting (XSS) vulnerability in Arachnys Cabot 0.11.12 can be exploited via the Address column.