Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6565-fg86-6jcx

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Django Cross-site Scripting Vulnerability

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by an @property.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.7.6

1.7.6

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.8a1, < 1.8b2

1.8b2

EPSS

Процентиль: 49%
0.00257
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

redhat
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

nvd
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

debian
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in a ...

EPSS

Процентиль: 49%
0.00257
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79