2024-07-14 02:06:08 +00:00

64 lines
2.4 KiB
JSON

{
"id": "CVE-2024-30248",
"sourceIdentifier": "security-advisories@github.com",
"published": "2024-04-02T15:15:53.293",
"lastModified": "2024-04-02T18:12:16.283",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. As a default, SVG is an allowed file type for upload. An attacker can upload an SVG which when loaded can allow arbitrary access to the admin page. This vulnerability was patched in version 1.3.2."
},
{
"lang": "es",
"value": "Piccolo Admin es una interfaz de administraci\u00f3n/sistema de gesti\u00f3n de contenido para Python, construido sobre Piccolo. El panel de administraci\u00f3n de Piccolo permite cargar archivos multimedia. De forma predeterminada, SVG es un tipo de archivo permitido para cargar. Un atacante puede cargar un SVG que, cuando se carga, puede permitir el acceso arbitrario a la p\u00e1gina de administraci\u00f3n. Esta vulnerabilidad fue parcheada en la versi\u00f3n 1.3.2."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 7.7,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.3,
"impactScore": 5.8
}
]
},
"weaknesses": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://github.com/piccolo-orm/piccolo_admin/commit/c419575c2467959d906154084d305648eb2b8faf",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/piccolo-orm/piccolo_admin/security/advisories/GHSA-pmww-v6c9-7p83",
"source": "security-advisories@github.com"
}
]
}