github.com
https://github.com/arachnys/cabot CVE-2020-7734
Cross-site Scripting (XSS)
Record summary
EIP currently links 1 catalogued exploit to CVE-2020-7734.
Description
All versions of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
cabot | CVE List | Version range not supplied | affected |
cabotBrowse PyPI / cabot | GitHub Advisory | Through 0.11.16 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCabot 0.11.12 - Persistent Cross-Site ScriptingExploitDB exploitby Abhiram VNot analyzed1 file
References
8github.com
https://github.com/arachnys/cabot/commit/eb0b3544f8c8ab2dee4643df191da346a941734f github.com
https://github.com/arachnys/cabot/pull/694 github.com
https://github.com/pypa/advisory-database/tree/main/vulns/cabot/PYSEC-2020-227.yaml itsmeanonartist.tech
https://itsmeanonartist.tech/blogs/blog2.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-7734 snyk.io
https://snyk.io/vuln/SNYK-PYTHON-CABOT-609862 exploit-db.com
https://www.exploit-db.com/exploits/48791