CVE-2009-5145: XSS
Published Aug 7, 2017
·Updated
Cross-site scripting (XSS) vulnerability in ZMI pages that use the managetabsmessage in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.
Affected Software
12 affected componentsFixes available
pip/Zope2<2.12.5
2.12.5
debian/zope2.12
Zope Zope=2.10.1
Zope Zope=2.10.2
Zope Zope=2.10.4
Zope Zope=2.10.5
Zope Zope=2.10.6
Zope Zope=2.10.7
Zope Zope=2.10.9
Zope Zope=2.11.2
Zope Zope=2.11.4
Zope Zope=2.12.0
Event History
Aug 7, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
May 2, 2022
Advisory Published
via GitHub·04:01 AM
Nov 21, 2024
Data Sourced
via Debian·11:38 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-5145?
CVE-2009-5145 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2009-5145?
To fix CVE-2009-5145, upgrade to Zope version 2.12.5 or later.
3
What are the affected versions in CVE-2009-5145?
CVE-2009-5145 affects Zope versions 2.10.1 through 2.11.4.
4
What type of vulnerability is CVE-2009-5145?
CVE-2009-5145 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2009-5145 be exploited remotely?
Yes, CVE-2009-5145 can be exploited remotely via crafted input.