wsgidav is vulnerable to Cross-Site Scripting (XSS) when directory browsing is enabled
CVE-2022-41905

8.2HIGH

Key Information:

Vendor

Mar10

Status
Vendor
CVE Published:
11 November 2022

What is CVE-2022-41905?

WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks. This issue has been patched, users can upgrade to version 4.1.0. As a workaround, set dir_browser.enable = False in the configuration.

Affected Version(s)

wsgidav >= 3.0.0a1, < 4.1.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.