CVE-2023-42458

LOW

Zope < 4.8.10 - Basic XSS

Title source: rule
STIX 2.1

Description

Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG images. Note that an image tag with an SVG image as source is never vulnerable, even when the SVG image contains malicious code. To exploit the vulnerability, an attacker would first need to upload an image, and then trick a user into following a specially crafted link. Patches are available in Zope 4.8.10 and 5.8.5. As a workaround, make sure the "Add Documents, Images, and Files" permission is only assigned to trusted roles. By default, only the Manager has this permission.

Scores

CVSS v3 3.7
EPSS 0.0032
EPSS Percentile 55.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (2)
pypi/Zope 0 - 4.8.10PyPI
zope/zope < 4.8.10
Published Sep 21, 2023
Tracked Since Feb 18, 2026