PT-2019-17655 · Buttle · Buttle
Bl4De
+1
·
Published
2019-04-03
·
Updated
2019-10-09
·
CVE-2019-5422
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
buttle version 0.2.0
buttle versions prior to a fixed version (no fixed version specified)
Description
The issue allows execution of attacker-provided code in the victim's browser. This occurs when an attacker creates an arbitrary file on the server, exploiting the failure to sanitize filenames. This enables attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code.
Recommendations
For buttle version 0.2.0, consider using an alternative package until a fix is made available.
For buttle versions prior to a fixed version, consider using an alternative package until a fix is made available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buttle