{"id":"CVE-2009-5145","aliases":[],"url":"https://o3.security/vulnerability/CVE-2009-5145","summary":"Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.","details":"Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.","published":"2017-08-07T17:29:00.173","modified":"2026-06-16T23:15:10.077","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/zopefoundation/Zope/commit/2abdf14620f146857dc8e3ffd2b6a754884c331d","label":"zopefoundation/Zope@2abdf14"},"references":[{"type":"ADVISORY","url":"http://cve.killedkenny.io/cve/CVE-2009-5145"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2015/03/02/7"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/72792/info"},{"type":"ADVISORY","url":"https://bugs.launchpad.net/zope2/+bug/490514"},{"type":"ADVISORY","url":"https://github.com/zopefoundation/Zope/commit/2abdf14620f146857dc8e3ffd2b6a754884c331d"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2009-5145/"},{"type":"ADVISORY","url":"http://cve.killedkenny.io/cve/CVE-2009-5145"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2015/03/02/7"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/72792/info"},{"type":"ADVISORY","url":"https://bugs.launchpad.net/zope2/+bug/490514"},{"type":"ADVISORY","url":"https://github.com/zopefoundation/Zope/commit/2abdf14620f146857dc8e3ffd2b6a754884c331d"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2009-5145/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:15:10.077"}}