CVE-2011-1157: XSS
Published Apr 11, 2011
·Updated
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via malformed XML comments.
Affected Software
2 affected componentsFixes available
pip/feedparser>=5.0<5.0.1
5.0.1
Mark Pilgrim Feedparser=5.0
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Apr 11, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Jul 23, 2018
Advisory Published
via GitHub·07:52 PM
Frequently Asked Questions
1
What is the severity of CVE-2011-1157?
The severity of CVE-2011-1157 is rated as medium with a score of 6.1.
2
What type of vulnerability is CVE-2011-1157?
CVE-2011-1157 is a cross-site scripting (XSS) vulnerability that affects feedparser.py in Universal Feed Parser.
3
How can I fix CVE-2011-1157?
To fix CVE-2011-1157, you should update to Universal Feed Parser version 5.0.1 or later where a patch is available.
4
What can attackers do with CVE-2011-1157?
Attackers can exploit CVE-2011-1157 to inject arbitrary web scripts or HTML through malformed XML comments.
5
Which software is affected by CVE-2011-1157?
CVE-2011-1157 affects the feedparser library, specifically versions before 5.0.1.