Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

Cross-site Scripting in OctoPrint

GHSA-x7r7-wmj8-vv5g · CVE-2022-1430 · PYSEC-2022-200

Published · Modified

Description

Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0. The login endpoint allows for javascript injection which may lead to account takeover in a phishing scenario.

Ready to move

Start Securing

Free, no credit card | First findings in minutes