{"id":"GHSA-v7q8-wvvh-c97p","summary":"Moderate severity vulnerability that affects Zope2","details":"Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.","aliases":["CVE-2010-1104","PYSEC-2026-765"],"modified":"2026-07-06T08:11:38.678927865Z","published":"2018-07-23T19:51:28Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:57:13Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2010-1104"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55599"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v7q8-wvvh-c97p"},{"type":"WEB","url":"https://mail.zope.org/pipermail/zope-announce/2010-January/002229.html"},{"type":"WEB","url":"http://secunia.com/advisories/38007"},{"type":"WEB","url":"http://www.osvdb.org/61655"},{"type":"WEB","url":"http://www.securityfocus.com/bid/37765"},{"type":"WEB","url":"http://www.vupen.com/english/advisories/2010/0104"}],"affected":[{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.8.0"},{"fixed":"2.8.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-v7q8-wvvh-c97p/GHSA-v7q8-wvvh-c97p.json"}},{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.9.0"},{"fixed":"2.9.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-v7q8-wvvh-c97p/GHSA-v7q8-wvvh-c97p.json"}},{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.10.0"},{"fixed":"2.10.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-v7q8-wvvh-c97p/GHSA-v7q8-wvvh-c97p.json"}},{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.11.0"},{"fixed":"2.11.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-v7q8-wvvh-c97p/GHSA-v7q8-wvvh-c97p.json"}},{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.12.0"},{"fixed":"2.12.3"}]}],"versions":["2.12.0","2.12.1","2.12.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-v7q8-wvvh-c97p/GHSA-v7q8-wvvh-c97p.json"}}],"schema_version":"1.9.0"}