VDB

CVE-2023-34457

CVE-2023-34457 PUBLISHED CVSS 5.900000095367432 MEDIUM

MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form

EPSS 1.08% · 62.0th percentile

Risk Scores

CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.08%
62.0th percentile

Affected Products

VendorProductVersions
PyPIMechanicalSoup0.2.0
mechanicalsoup_projectmechanicalsoup0.2.0
MechanicalSoupMechanicalSoup>= 0.2.0, < 1.3.0
mechanicalsoup_projectmechanicalsoup0

Timeline

  • Jul 5, 2023 CVE Published
  • Jul 6, 2023 EPSS Score
  • Aug 10, 2023 EPSS Score
  • Oct 18, 2023 EPSS Score
  • Nov 22, 2023 EPSS Score
  • Jan 31, 2024 EPSS Score
  • Mar 6, 2024 EPSS Score
  • Apr 10, 2024 EPSS Score
  • Jun 18, 2024 EPSS Score
  • Jul 23, 2024 EPSS Score
  • Aug 27, 2024 EPSS Score
  • Oct 1, 2024 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›