PT-2022-8066 · Pypi · Yolapi
Published
2022-12-28
·
Updated
2024-05-17
·
CVE-2018-25056
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
yolapi (affected versions not specified)
Description
A problematic vulnerability was found in yolapi, affecting the
render description function of the file yolapi/pypi/metadata.py. The manipulation of the text argument leads to cross-site scripting. It is possible to launch the attack remotely.Recommendations
To fix this issue, it is recommended to apply a patch with the name a0fe129055a99f429133a5c40cb13b44611ff796. As a temporary workaround, consider disabling the
render description function until a patch is available. Restrict access to the vulnerable file yolapi/pypi/metadata.py to minimize the risk of exploitation. Avoid using the text argument in the affected function until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yolapi