CVE-2023-44389
Zope management interface vulnerable to stored cross site scripting via the title property
Severity Score
4.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI). All versions of Zope 4 and Zope 5 are affected. Patches will be released with Zope versions 4.8.11 and 5.8.6.
Zope es un servidor de aplicaciones web de código abierto. La propiedad title, disponible en la mayoría de los objetos Zope, se puede utilizar para almacenar código de script que se ejecuta mientras se visualiza el objeto afectado en Zope Management Interface (ZMI). Todas las versiones de Zope 4 y Zope 5 se ven afectadas. Los parches se lanzarán con las versiones 4.8.11 y 5.8.6 de Zope.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-09-28 CVE Reserved
- 2023-10-04 CVE Published
- 2024-08-02 CVE Updated
- 2024-10-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/zopefoundation/Zope/security/advisories/GHSA-m755-gxxg-r5qh | 2024-02-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zope Search vendor "Zope" | Zope Search vendor "Zope" for product "Zope" | >= 4.0 < 4.8.11 Search vendor "Zope" for product "Zope" and version " >= 4.0 < 4.8.11" | - |
Affected
| ||||||
Zope Search vendor "Zope" | Zope Search vendor "Zope" for product "Zope" | >= 5.0 < 5.8.6 Search vendor "Zope" for product "Zope" and version " >= 5.0 < 5.8.6" | - |
Affected
|