CVE-2025-23213

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed in 1.5.28.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-28 16:15

Updated : 2025-05-08 18:46


NVD link : CVE-2025-23213

Mitre link : CVE-2025-23213

CVE.ORG link : CVE-2025-23213


JSON object : View

Products Affected

tandoor

  • recipes
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type