Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22414

Опубликовано: 17 янв. 2024
Источник: nvd
CVSS3: 6.5
CVSS3: 5.4
EPSS Низкий

Описание

flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the /user/<user> page allows a user's comments to execute arbitrary javascript code. The html template user.html contains the following code snippet to render comments made by a user: <div class="content" tag="content">{{comment[2]|safe}}</div>. Use of the "safe" tag causes flask to not escape the rendered content. To remediate this, simply remove the |safe tag from the HTML above. No fix is is available and users are advised to manually edit their installation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dogukanurker:flaskblog:*:*:*:*:*:*:*:*
Версия до 1.1.0 (включая)

EPSS

Процентиль: 42%
0.002
Низкий

6.5 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 42%
0.002
Низкий

6.5 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79