CVE-2023-33175 is a high-severity vulnerability affecting ToUI versions 2.0.1 to 2.4.0, a Python package for building user interfaces. The vulnerability, stemming from improper use of Flask-Caching (SimpleCache) for user variables, allows for unauthorized information disclosure. With a CVSS score of 7.5, it can be exploited remotely with low attack complexity, potentially leading to full confidentiality compromise. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using affected ToUI versions should upgrade to 2.4.1 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.1, <= 2.4.0CPE matchmatch criteria | cpe:2.3:a:toui_project:toui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.