GHSA-m755-gxxg-r5qh

Suggest an improvement
Source
https://github.com/advisories/GHSA-m755-gxxg-r5qh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-m755-gxxg-r5qh/GHSA-m755-gxxg-r5qh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m755-gxxg-r5qh
Aliases
Related
Published
2023-10-04T18:50:25Z
Modified
2024-11-19T19:24:12.687854Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Zope management interface vulnerable to stored cross site scripting via the title property
Details

Impact

The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI) because the title property is displayed unquoted in the breadcrumbs element. All versions of Zope 4 and Zope 5 are affected.

Patches

Patches will be released with Zope versions 4.8.11 and 5.8.6.

Workarounds

Make sure only Manager users can edit and view Zope objects in the Zope Management Interface. This is the default.

Database specific
{
    "severity": "LOW",
    "github_reviewed_at": "2023-10-04T18:50:25Z",
    "nvd_published_at": "2023-10-04T21:15:10Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true
}
References

Affected packages

PyPI / zope

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.8.11

Affected versions

4.*

4.0
4.1
4.1.1
4.1.2
4.1.3
4.2
4.2.1
4.3
4.4
4.4.1
4.4.2
4.4.3
4.4.4
4.5
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.6
4.6.1
4.6.2
4.6.3
4.7
4.8
4.8.1
4.8.2
4.8.3
4.8.4
4.8.5
4.8.6
4.8.7
4.8.8
4.8.9
4.8.10

PyPI / zope

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.8.6

Affected versions

5.*

5.0
5.1
5.1.1
5.1.2
5.2
5.2.1
5.3
5.4
5.5
5.5.1
5.5.2
5.6
5.7
5.7.1
5.7.2
5.7.3
5.8
5.8.1
5.8.2
5.8.3
5.8.4
5.8.5