Логотип exploitDog
bind:"GHSA-37hp-765x-j95x" OR bind:"CVE-2017-7233"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-37hp-765x-j95x" OR bind:"CVE-2017-7233"

Количество 7

Количество 7

github логотип

GHSA-37hp-765x-j95x

больше 6 лет назад

Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-7233

больше 8 лет назад

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2017-7233

больше 8 лет назад

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-7233

больше 8 лет назад

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-7233

больше 8 лет назад

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 re ...

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:0826-1

больше 7 лет назад

Security update for python-Django

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:0824-1

больше 7 лет назад

Security update for python3-Django

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37hp-765x-j95x

Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 re ...

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2018:0826-1

Security update for python-Django

больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:0824-1

Security update for python3-Django

больше 7 лет назад

Уязвимостей на страницу