CVE-2020-7734 – cabot
Package
Manager: pip
Name: cabot
Vulnerable Version: >=0 <=0.11.16
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:L/E:U
EPSS: 0.01413 pctl0.79805
Details
Cabot Cross Site Scripting (XSS) vulnerability via Endpoint column All versions up to 0.11.16 of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column.
Metadata
Created: 2022-05-24T17:29:11Z
Modified: 2024-09-13T15:56:14Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mqwh-r366-4224/GHSA-mqwh-r366-4224.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-mqwh-r366-4224
Finding: F008
Auto approve: 1