Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0143 | MechanicalSoup is a Python library for automating interaction with websites. Starting in version 0.2.0 and prior to version 1.3.0, a malicious web server can read arbitrary files on the client using a `<input type="file" ...>` inside HTML form. All users of MechanicalSoup's form submission are affected, unless they took very specific (and manual) steps to reset HTML form field values. Version 1.3.0 contains a patch for this issue. |
Github GHSA |
GHSA-x456-3ccm-m6j4 | MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form |
Thu, 24 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T16:55:35.658Z
Reserved: 2023-06-06T16:16:53.559Z
Link: CVE-2023-34457
Updated: 2024-08-02T16:10:06.995Z
Status : Modified
Published: 2023-07-05T20:15:10.343
Modified: 2024-11-21T08:07:17.630
Link: CVE-2023-34457
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA