CVE-2023-0488Cross-site Scripting in Pyload

Severity
5.4MEDIUMNVD
EPSS
0.4%
top 41.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26
Latest updateJan 27

Description

Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages4 packages

NVDpyload/pyload< 2023-01-24
CVEListV5pyload/pyload_pyloadunspecified0.5.0b3.dev42
NVDpyload-ng_project/pyload-ng< 0.5.0b3.dev42
PyPIpyload-ng_project/pyload-ng< 0.5.0b3.dev42

Patches

🔴Vulnerability Details

3
OSV
Cross-site Scripting in pyload-ng2023-01-27
GHSA
Cross-site Scripting in pyload-ng2023-01-27
CVEList
Cross-site Scripting (XSS) - Stored in pyload/pyload2023-01-26
CVE-2023-0488 — Cross-site Scripting in Pyload Pyload | cvebase