Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-94928
HistoryAug 17, 2021 - 12:00 a.m.

Quokka XML External Entity Injection Vulnerability

2021-08-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
6

0.006 Low

EPSS

Percentile

79.1%

Quokka is a content management framework written in Python. quokka version 0.4.0 is vulnerable to XML external entity injection. A remote attacker can exploit this vulnerability to execute arbitrary code via the quokka/core/content/views.py component.

CPENameOperatorVersion
quokka quokkaeq0.4.0

0.006 Low

EPSS

Percentile

79.1%

Related for CNVD-2021-94928