CVE-2024-23341

MEDIUM

TuiTse-TsuSin < 1.3.2 - Cross-Site Scripting via Unquoted Input in tuitse_html

Title source: llm
STIX 2.1

Description

TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, and extracting sentences of the Taiwanese Chinese characters and the Roman characters. Prior to version 1.3.2, when using `tuitse_html` without quoting the input, there is a html injection vulnerability. Version 1.3.2 contains a patch for the issue. As a workaround, sanitize Taigi input with HTML quotation.

Scores

CVSS v3 6.1
EPSS 0.0050
EPSS Percentile 66.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
ithuan/tuitse-tsusin < 1.3.2
pypi/TuiTse-TsuSin 0 - 1.3.2PyPI
Published Jan 23, 2024
Tracked Since Feb 18, 2026