Junglewise Threat Intelligence

CVE-2020-18705: PYSEC-2021-145 - XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.

CVE-2020-18705 · Severity: low · CVSS 3.1 · Published 2021-08-16

Technologies: quokka (PyPI). Vendors: PyPI.

Executive brief

XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.

Affected products

  • PyPI quokka

Related threats