{"id":"PYSEC-2024-100","details":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition.","aliases":["CVE-2024-43795","GHSA-vfj8-5pj7-2f9g"],"modified":"2024-10-08T17:57:19.304148Z","published":"2024-10-02T20:15:00Z","references":[{"type":"ADVISORY","url":"https://github.com/OpenC3/cosmos/security/advisories/GHSA-vfj8-5pj7-2f9g"},{"type":"FIX","url":"https://github.com/OpenC3/cosmos/commit/762d7e0e93bdc2f340b1e42acccedc78994a576e"}],"affected":[{"package":{"name":"openc3","ecosystem":"PyPI","purl":"pkg:pypi/openc3"},"ranges":[{"type":"GIT","repo":"https://github.com/OpenC3/cosmos","events":[{"introduced":"0"},{"fixed":"762d7e0e93bdc2f340b1e42acccedc78994a576e"}]},{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.19.0"}]}],"versions":["0.1.0","5.10.0","5.10.1","5.11.0","5.11.1","5.11.2","5.11.3","5.12.0","5.13.0","5.14.0","5.14.1","5.14.2","5.15.0","5.15.1","5.15.2","5.16.0","5.16.1","5.16.2","5.17.0","5.17.1","5.18.0","5.9.2b0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/openc3/PYSEC-2024-100.yaml"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}