id: PYSEC-2020-226 details: Cross Site Scripting (XSS) vulnerability in Arachnys Cabot 0.11.12 can be exploited via the Address column. affected: - package: name: cabot ecosystem: PyPI purl: pkg:pypi/cabot ranges: - type: ECOSYSTEM events: - introduced: "0" versions: - 0.10.0 - 0.10.1 - 0.10.2 - 0.10.3 - 0.10.4 - 0.10.5 - 0.10.6 - 0.10.7 - 0.10.8 - 0.11.1 - 0.11.10 - 0.11.12 - 0.11.2 - 0.11.3 - 0.11.4 - 0.11.5 - 0.11.6 - 0.11.7 - 0.11.8 - 0.11.9 - 0.6.0 - 0.8.4 - 0.8.5 - 0.8.6 - 0.8.7 - 0.9.0 - 0.9.1 - 0.9.2 references: - type: ARTICLE url: https://itsmeanonartist.tech/blogs/blog2.html - type: WEB url: https://www.exploit-db.com/exploits/48791 - type: WEB url: https://www.exploitalert.com/view-details.html?id=36106 - type: WEB url: https://packetstormsecurity.com/files/159070/Cabot-0.11.12-Cross-Site-Scripting.html - type: ADVISORY url: https://github.com/advisories/GHSA-8q2h-4mq6-396j aliases: - CVE-2020-25449 - GHSA-8q2h-4mq6-396j modified: "2021-08-27T03:21:56.543783Z" published: "2020-12-04T20:15:00Z"