CVE-2023-33175

ToUI is a Python package for creating user interfaces (websites and desktop apps) from HTML. ToUI is using Flask-Caching (SimpleCache) to store user variables. Websites that use `Website.user_vars` property. It affects versions 2.0.1 to 2.4.0. This issue has been patched in version 2.4.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:toui_project:toui:*:*:*:*:*:*:*:*

History

07 Jun 2023, 17:21

Type Values Removed Values Added
CWE CWE-913
First Time Toui Project toui
Toui Project
CPE cpe:2.3:a:toui_project:toui:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://github.com/mubarakalmehairbi/ToUI/releases/tag/v2.4.1 - (MISC) https://github.com/mubarakalmehairbi/ToUI/releases/tag/v2.4.1 - Release Notes
References (MISC) https://github.com/mubarakalmehairbi/ToUI/security/advisories/GHSA-hh7j-pg39-q563 - (MISC) https://github.com/mubarakalmehairbi/ToUI/security/advisories/GHSA-hh7j-pg39-q563 - Vendor Advisory

30 May 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-30 05:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-33175

Mitre link : CVE-2023-33175

CVE.ORG link : CVE-2023-33175


JSON object : View

Products Affected

toui_project

  • toui
CWE
CWE-913

Improper Control of Dynamically-Managed Code Resources

CWE-914

Improper Control of Dynamically-Identified Variables