Описание
MechanicalSoup is a Python library for automating interaction with websites. Starting in version 0.2.0 and prior to version 1.3.0, a malicious web server can read arbitrary files on the client using a <input type="file" ...> inside HTML form. All users of MechanicalSoup's form submission are affected, unless they took very specific (and manual) steps to reset HTML form field values. Version 1.3.0 contains a patch for this issue.
Ссылки
- Patch
- Release Notes
- ExploitPatchVendor Advisory
- Patch
- Release Notes
- ExploitPatchVendor Advisory
Уязвимые конфигурации
EPSS
5.9 Medium
CVSS3
7.5 High
CVSS3
Дефекты
Связанные уязвимости
MechanicalSoup is a Python library for automating interaction with websites. Starting in version 0.2.0 and prior to version 1.3.0, a malicious web server can read arbitrary files on the client using a `<input type="file" ...>` inside HTML form. All users of MechanicalSoup's form submission are affected, unless they took very specific (and manual) steps to reset HTML form field values. Version 1.3.0 contains a patch for this issue.
MechanicalSoup is a Python library for automating interaction with web ...
MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
EPSS
5.9 Medium
CVSS3
7.5 High
CVSS3