CVE-2009-5145Medium· 6.1▾ SunlitZope Cross-site scripting (XSS) vulnerability in ZMI pages
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.1%
2.1% → 2.4%
Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.
zope2 < 2.12.5Upgrade to a patched release:
zope2 2.12.5Connected by shared product, vendor, weakness, or advisory.