CVE-2019-16935

⚪ Do wiadomości

Wykorzystanie XSS w serwerze XML-RPC w Pythonie umożliwia dostarczenie złośliwego JavaScriptu.

CVSS
6.1
EPSS
4.7%
Exploit
poc
Vendor
canonical
Opis źródłowy (NVD)

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

exploit xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)4.7%
Opublikowano (NVD)2019-09-28 02:15:10 UTC
Ostatnia modyfikacja (NVD)2026-10-07 19:17:12 UTC
Referencje