CVE-2025-23213

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed in 1.5.28.
Configurations

No configuration.

History

28 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-28 16:15

Updated : 2025-01-28 16:15


NVD link : CVE-2025-23213

Mitre link : CVE-2025-23213

CVE.ORG link : CVE-2025-23213


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type