Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m755-gxxg-r5qh

Опубликовано: 04 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

Zope management interface vulnerable to stored cross site scripting via the title property

Impact

The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI) because the title property is displayed unquoted in the breadcrumbs element. All versions of Zope 4 and Zope 5 are affected.

Patches

Patches will be released with Zope versions 4.8.11 and 5.8.6.

Workarounds

Make sure only Manager users can edit and view Zope objects in the Zope Management Interface. This is the default.

Пакеты

Наименование

Zope

pip
Затронутые версииВерсия исправления

>= 4.0.0, < 4.8.11

4.8.11

Наименование

Zope

pip
Затронутые версииВерсия исправления

>= 5.0.0, < 5.8.6

5.8.6

EPSS

Процентиль: 56%
0.00339
Низкий

3.1 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.1
nvd
больше 2 лет назад

Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI). All versions of Zope 4 and Zope 5 are affected. Patches will be released with Zope versions 4.8.11 and 5.8.6.

EPSS

Процентиль: 56%
0.00339
Низкий

3.1 Low

CVSS3

Дефекты

CWE-79