Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54qj-48vx-cr9f

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Django Cross-site scripting (XSS) vulnerability

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 0.91, < 0.91.2

0.91.2

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 0.95, < 0.95.3

0.95.3

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 0.96, < 0.96.2

0.96.2

EPSS

Процентиль: 62%
0.00441
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 17 лет назад

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

redhat
около 17 лет назад

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

nvd
около 17 лет назад

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

debian
около 17 лет назад

Cross-site scripting (XSS) vulnerability in the login form in the admi ...

EPSS

Процентиль: 62%
0.00441
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79