PT-2023-24892 · Pybb · Pybb

CVE-2023-34461

·

Publicado

2023-06-19

·

Atualizado

2023-06-27

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PyBB versions 0.1.0
Description A manual code review of the PyBB bulletin board server revealed a vulnerability that allows users to submit any type of HTML tag, which can be executed. For example, a malicious <a> tag, such as <a href=javascript:alert (1)>xss</a>, can be used to run code through JavaScript on the client side. Attackers need posting privilege to exploit this issue.
Recommendations For version 0.1.0, upgrade to version 0.1.1 to resolve the issue. As a temporary workaround for users unable to upgrade, consider removing the ability to create posts. Alternatively, remove the |safe tag from the Jinja2 template titled "post.html" in templates. Another option is to add manual validation of links in the post creation section.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-34461
GHSA-MV96-W49P-438P

Produtos afetados

Pybb