Логотип exploitDog
bind:CVE-2023-48699
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-48699

Количество 2

Количество 2

nvd логотип

CVE-2023-48699

около 2 лет назад

fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior to version 0.1.5, an attacker could modify the locators.ini locator file with python code that without proper validation it's executed and it could lead to rce. The vulnerability is in the function `def __locator__(self, locator_name: str)` in `page.py`. In order to mitigate this issue, upgrade to fastbots version 0.1.5 or above.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-vccg-f4gp-45x9

около 2 лет назад

Eval Injection in fastbots

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-48699

fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior to version 0.1.5, an attacker could modify the locators.ini locator file with python code that without proper validation it's executed and it could lead to rce. The vulnerability is in the function `def __locator__(self, locator_name: str)` in `page.py`. In order to mitigate this issue, upgrade to fastbots version 0.1.5 or above.

CVSS3: 8.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-vccg-f4gp-45x9

Eval Injection in fastbots

CVSS3: 8.4
1%
Низкий
около 2 лет назад

Уязвимостей на страницу