Логотип exploitDog
bind:CVE-2023-42458
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-42458

Количество 2

Количество 2

nvd логотип

CVE-2023-42458

больше 2 лет назад

Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG images. Note that an image tag with an SVG image as source is never vulnerable, even when the SVG image contains malicious code. To exploit the vulnerability, an attacker would first need to upload an image, and then trick a user into following a specially crafted link. Patches are available in Zope 4.8.10 and 5.8.5. As a workaround, make sure the "Add Documents, Images, and Files" permission is only assigned to trusted roles. By default, only the Manager has this permission.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-wm8q-9975-xh5v

больше 2 лет назад

Zope vulnerable to Stored Cross Site Scripting with SVG images

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-42458

Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG images. Note that an image tag with an SVG image as source is never vulnerable, even when the SVG image contains malicious code. To exploit the vulnerability, an attacker would first need to upload an image, and then trick a user into following a specially crafted link. Patches are available in Zope 4.8.10 and 5.8.5. As a workaround, make sure the "Add Documents, Images, and Files" permission is only assigned to trusted roles. By default, only the Manager has this permission.

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-wm8q-9975-xh5v

Zope vulnerable to Stored Cross Site Scripting with SVG images

CVSS3: 3.7
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу