Junglewise Threat Intelligence

PYSEC-2023-294 - An XSS vulnerability has been detected in Repox, which allows an attacker to compromise interactions between a user and the vulnerable appli

Severity: low · CVSS 3.1 · Published 2023-12-13

Technologies: repox (PyPI). Vendors: PyPI.

Executive brief

An XSS vulnerability has been detected in Repox, which allows an attacker to compromise interactions between a user and the vulnerable application, and can be exploited by a third party by sending a specially crafted JavaScript payload to a user, and thus gain full control of their session.

Affected products

  • PyPI repox

Related threats