Логотип exploitDog
bind:CVE-2023-27494
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-27494

Количество 2

Количество 2

nvd логотип

CVE-2023-27494

почти 3 года назад

Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. Users of hosted Streamlit app(s) were vulnerable to a reflected XSS vulnerability. An attacker could craft a malicious URL with Javascript payloads to a Streamlit app. The attacker could then trick the user into visiting the malicious URL and, if successful, the server would render the malicious javascript payload as-is, leading to XSS. Version 0.81.0 contains a patch for this vulnerability.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-9c6g-qpgj-rvxw

почти 3 года назад

Streamlit publishes previously-patched Cross-site Scripting vulnerability

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-27494

Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. Users of hosted Streamlit app(s) were vulnerable to a reflected XSS vulnerability. An attacker could craft a malicious URL with Javascript payloads to a Streamlit app. The attacker could then trick the user into visiting the malicious URL and, if successful, the server would render the malicious javascript payload as-is, leading to XSS. Version 0.81.0 contains a patch for this vulnerability.

CVSS3: 5.9
1%
Низкий
почти 3 года назад
github логотип
GHSA-9c6g-qpgj-rvxw

Streamlit publishes previously-patched Cross-site Scripting vulnerability

CVSS3: 5.9
1%
Низкий
почти 3 года назад

Уязвимостей на страницу