CVE-2023-44389
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
04/10/2023
Last modified:
01/02/2024
Description
Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI). All versions of Zope 4 and Zope 5 are affected. Patches will be released with Zope versions 4.8.11 and 5.8.6.
Impact
Base Score 3.x
4.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:* | 4.0 (including) | 4.8.11 (excluding) |
| cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:* | 5.0 (including) | 5.8.6 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



