CVE-2023-44389

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
04/10/2023
Last modified:
01/02/2024

Description

Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI). All versions of Zope 4 and Zope 5 are affected. Patches will be released with Zope versions 4.8.11 and 5.8.6.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:* 4.0 (including) 4.8.11 (excluding)
cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:* 5.0 (including) 5.8.6 (excluding)