NA

CVE-2023-34457

Published: 05/07/2023 Updated: 03/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

MechanicalSoup is a Python library for automating interaction with websites. Starting in version 0.2.0 and prior to version 1.3.0, a malicious web server can read arbitrary files on the client using a `<input type="file" ...>` inside HTML form. All users of MechanicalSoup's form submission are affected, unless they took very specific (and manual) steps to reset HTML form field values. Version 1.3.0 contains a patch for this issue.

Vulnerable Product Search on Vulmon Subscribe to Product

mechanicalsoup project mechanicalsoup

Vendor Advisories

Debian Bug report logs - #1041814 python-mechanicalsoup: CVE-2023-34457 Package: src:python-mechanicalsoup; Maintainer for src:python-mechanicalsoup is Debian Python Team &lt;team+python@trackerdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Sun, 23 Jul 2023 20:09:01 UTC Severity: grave Tags: s ...