Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m34-jcjv-45xf

Опубликовано: 05 июн. 2020
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

XSS in Django

An issue was discovered in Django version 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 2.2a1, < 2.2.13

2.2.13

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 3.0a1, < 3.0.7

3.0.7

EPSS

Процентиль: 76%
0.00992
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.5
redhat
больше 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.1
nvd
больше 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.1
debian
больше 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0 ...

fstec
больше 5 лет назад

Уязвимость реализации функции ForeignKeyRawIdWidget библиотеки Django, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 76%
0.00992
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79