CVE-2025-23213

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed in 1.5.28.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*

History

08 May 2025, 18:46

Type Values Removed Values Added
References () https://github.com/TandoorRecipes/recipes/commit/3e37d11c6a3841a00eb27670d1d003f1a713e1cf - () https://github.com/TandoorRecipes/recipes/commit/3e37d11c6a3841a00eb27670d1d003f1a713e1cf - Patch
References () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-56jp-j3x5-hh2w - () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-56jp-j3x5-hh2w - Exploit, Vendor Advisory
First Time Tandoor
Tandoor recipes
CPE cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

28 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-28 16:15

Updated : 2025-05-08 18:46


NVD link : CVE-2025-23213

Mitre link : CVE-2025-23213


JSON object : View

Products Affected

tandoor

  • recipes
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type