logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-34457

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-34457

Description:
MechanicalSoup is a Python library for automating interaction with websites. Starting in version 0.2.0 and prior to version 1.3.0, a malicious web server can read arbitrary files on the client using a `<input type="file" ...>` inside HTML form. All users of MechanicalSoup's form submission are affected, unless they took very specific (and manual) steps to reset HTML form field values. Version 1.3.0 contains a patch for this issue.
Last updated date:
08/03/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
07/12/2023
Reference url to background

https://github.com/MechanicalSoup/MechanicalSoup/security/advisories/GHSA-x456-3ccm-m6j4

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy