CVE-2025-23213

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed in 1.5.28.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*

History

08 May 2025, 18:46

Type Values Removed Values Added
Summary
  • (es) Tandoor Recipes es una aplicación para gestionar recetas, planificar comidas y crear listas de compras. La función de carga de archivos permite cargar archivos arbitrarios, incluida html y svg. Ambos pueden contener contenido malicioso (XSS payloads). Esta vulnerabilidad se solucionó en la versión 1.5.28.
CPE cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*
References () https://github.com/TandoorRecipes/recipes/commit/3e37d11c6a3841a00eb27670d1d003f1a713e1cf - () https://github.com/TandoorRecipes/recipes/commit/3e37d11c6a3841a00eb27670d1d003f1a713e1cf - Patch
References () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-56jp-j3x5-hh2w - () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-56jp-j3x5-hh2w - Exploit, Vendor Advisory
First Time Tandoor
Tandoor recipes

28 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-28 16:15

Updated : 2025-05-08 18:46


NVD link : CVE-2025-23213

Mitre link : CVE-2025-23213

CVE.ORG link : CVE-2025-23213


JSON object : View

Products Affected

tandoor

  • recipes
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type