Updated CVE-2023-1434

patch-10
Ruben Condor 2023-05-30 15:41:56 +03:00
parent 35976a124c
commit d74b4974ff
No known key found for this signature in database
GPG Key ID: E523C68AF4460EBD
1 changed files with 5 additions and 1 deletions

View File

@ -6,6 +6,10 @@ info:
severity: medium
reference:
- https://www.sonarsource.com/blog/odoo-get-your-content-type-right-or-else
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1434
classification:
cve-id: CVE-2023-1434
cwe-id: CWE-79
metadata:
max-request: 1
verified: "true"
@ -15,7 +19,7 @@ info:
http:
- method: GET
path:
- "{{BaseURL}}/web/set_profiling?profile=0&collector=<script>alert(document.domain)</script>"
- "{{BaseURL}}/web/set_profiling?profile=0&collectors=<script>alert(document.domain)</script>"
matchers-condition: and
matchers: