CVE-2010-2480 describes a Cross-Site Scripting (XSS) vulnerability in Mako versions prior to 0.3.4, impacting products like makotemplates. The flaw stems from Mako's reliance on Python's cgi.escape for XSS protection, which is insufficient against specific attack vectors involving single quotes and JavaScript onLoad event handlers within a BODY element. With a CVSS score of 4.3 (Medium), this vulnerability is remotely exploitable with medium attack complexity, potentially leading to information disclosure (partial impact) but not confidentiality or availability compromise. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.3.3CPE matchmatch criteria | cpe:2.3:a:makotemplates:mako:*:*:*:*:*:*:*:* | ||
0.1.0CPE matchmatch criteria | cpe:2.3:a:makotemplates:mako:0.1.0:-:*:*:*:*:*:* | ||
0.1.1CPE matchmatch criteria | cpe:2.3:a:makotemplates:mako:0.1.1:*:*:*:*:*:*:* | ||
0.1.2CPE matchmatch criteria | cpe:2.3:a:makotemplates:mako:0.1.2:*:*:*:*:*:*:* | ||
0.1.3CPE matchmatch criteria | cpe:2.3:a:makotemplates:mako:0.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.