Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Blaiserideout

#29704of 53,635
8.8Total CVSS
Vulnerabilities · 1
PT-2023-12419
8.8
2023-01-28
Unknown · Nyuccl Psiturk · CVE-2021-4315
**Name of the Vulnerable Software and Affected Versions** NYUCCL psiTurk versions up to 3.2.0 **Description** A critical issue has been found in NYUCCL psiTurk, affecting unknown code of the file psiturk/experiment.py. The manipulation of the `mode` argument leads to improper neutralization of special elements used in a template engine. The exploit has been disclosed to the public and may be used. Upgrading to version 3.2.1 is able to address this issue. **Recommendations** For NYUCCL psiTurk versions up to 3.2.0, upgrade to version 3.2.1 to address the issue. As a temporary workaround, consider restricting the manipulation of the `mode` argument in the affected file psiturk/experiment.py until the upgrade is applied.