Описание
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected XSS vulnerabilities in the login dialog and the standalone application key confirmation dialog. An attacker who successfully talked a victim into clicking on a specially crafted login link, or a malicious app running on a victim's computer triggering the application key workflow with specially crafted parameters and then redirecting the victim to the related standalone confirmation dialog could use this to retrieve or modify sensitive configuration settings, interrupt prints or otherwise interact with the OctoPrint instance in a malicious way. The above mentioned specific vulnerabilities of the login dialog and the standalone application key confirmation dialog have been patched in the bugfix release 1.10.3 by individual escaping of the detected locations. A global change throughout all of OctoPrint's templating system with the upcoming 1.11.0 rel
Ссылки
- Vendor Advisory
Уязвимые конфигурации
EPSS
5.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
Связанные уязвимости
OctoPrint provides a web interface for controlling consumer 3D printer ...
OctoPrint Vulnerable to Reflected XSS in Jinja2 Templates
EPSS
5.5 Medium
CVSS3
6.1 Medium
CVSS3