VDB

CVE-2023-34457

CVE-2023-34457 PUBLISHED CVSS 8.699999809265137 HIGH

MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form

EPSS 1.08% · 64.1th percentile

Risk Scores

CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS Score
1.08%
64.1th percentile

Affected Products

VendorProductVersions
PyPIMechanicalSoup0.2.0
mechanicalsoup_projectmechanicalsoup0.2.0
MechanicalSoupMechanicalSoup>= 0.2.0, < 1.3.0
mechanicalsoup_projectmechanicalsoup0

Timeline

  • Jul 5, 2023 CVE Published
  • Jul 6, 2023 EPSS Score
  • Aug 10, 2023 EPSS Score
  • Oct 20, 2023 EPSS Score
  • Nov 25, 2023 EPSS Score
  • Feb 3, 2024 EPSS Score
  • Mar 10, 2024 EPSS Score
  • Apr 14, 2024 EPSS Score
  • Jun 24, 2024 EPSS Score
  • Jul 29, 2024 EPSS Score
  • Oct 1, 2024 CVE Updated
  • Oct 8, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›