High severity8.2NVD Advisory· Published Nov 11, 2022· Updated Jun 17, 2026
CVE-2022-41905
CVE-2022-41905
Description
WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks. This issue has been patched, users can upgrade to version 4.1.0. As a workaround, set dir_browser.enable = False in the configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wsgidavPyPI | >= 3.0.0a1, < 4.1.0 | 4.1.0 |
Affected products
2- mar10/wsgidavv5Range: >= 3.0.0a1, < 4.1.0
Patches
Vulnerability mechanics
References
5- github.com/mar10/wsgidav/commit/e9606ab0f42f4c1a6611bc3c52de299b0aba7726nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-xx6g-jj35-pxjvghsaADVISORY
- github.com/mar10/wsgidav/security/advisories/GHSA-xx6g-jj35-pxjvnvdMitigationThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-41905ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/wsgidav/PYSEC-2022-43018.yamlghsaWEB
News mentions
0No linked articles in our index yet.