Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m34-jcjv-45xf

Опубликовано: 05 июн. 2020
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

XSS in Django

An issue was discovered in Django version 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 2.2a1, < 2.2.13

2.2.13

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 3.0a1, < 3.0.7

3.0.7

EPSS

Процентиль: 77%
0.0108
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.5
redhat
около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.1
nvd
около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.1
debian
около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0 ...

fstec
около 5 лет назад

Уязвимость реализации функции ForeignKeyRawIdWidget библиотеки Django, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 77%
0.0108
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79