HIGH
Tandoor Recipes - Stored XSS through Unrestricted File Upload
Published Jan 28, 2025
8.7
HIGHCVSS 3.1
EPSS 0.37%
Description
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed in 1.5.28.
Affected products
-
- Version < 1.5.28StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TandoorRecipes | Recipes | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/TandoorRecipes/recipes/commit/3e37d11c6a3841a00eb27670d1d003f1a713e1cf x_refsource_MISCPatch
- https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-56jp-j3x5-hh2w x_refsource_CONFIRMExploitVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/TandoorRecipes/recipes/commit/3e37d11c6a3841a00eb27670d1d003f1a713e1cf | x_refsource_MISCPatch | |
| https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-56jp-j3x5-hh2w | x_refsource_CONFIRMExploitVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jan 28, 2025
Updated Jan 28, 2025
Reserved Jan 13, 2025
Link CVE-2025-23213
CISA Vulnrichment
Updated Jan 28, 2025