Executive brief
OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.
Affected products
- PyPI OctoPrint
Junglewise Threat Intelligence
CVE-2021-32561 · Severity: low · CVSS 3.1 · Published 2021-05-11
Technologies: OctoPrint (PyPI). Vendors: PyPI.
OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.