Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-94927
HistoryAug 17, 2021 - 12:00 a.m.

Quokka XML External Entity Injection Vulnerability (CNVD-2021-94927)

2021-08-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
5
quokka
xml
external entity injection
vulnerability
python
content management
remote attacker
arbitrary code
cnvd-2021-94927

EPSS

0.007

Percentile

79.9%

Quokka is a content management framework written in Python. quokka version 0.4.0 is vulnerable to XML external entity injection. A remote attacker can exploit this vulnerability to execute arbitrary code via the quokka/utils/atom.py component.

EPSS

0.007

Percentile

79.9%

Related for CNVD-2021-94927