Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4m5-j36m-8x72

Опубликовано: 22 янв. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

html injection vulnerability in the tuitse_html function.

Impact

When using tuitse_html without quoting the input, there is a html injection vulnerability. It should use the django version django.utils.html.format_html, instead of string.format()

Patches

Upgrade to version 1.3.2.

Workarounds

Sanitizing Taigi input with HTML quotation.

References

https://github.com/i3thuan5/TuiTse-TsuSin/pull/22

Пакеты

Наименование

TuiTse-TsuSin

pip
Затронутые версииВерсия исправления

< 1.3.2

1.3.2

EPSS

Процентиль: 65%
0.00495
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 2 лет назад

TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, and extracting sentences of the Taiwanese Chinese characters and the Roman characters. Prior to version 1.3.2, when using `tuitse_html` without quoting the input, there is a html injection vulnerability. Version 1.3.2 contains a patch for the issue. As a workaround, sanitize Taigi input with HTML quotation.

EPSS

Процентиль: 65%
0.00495
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79