Lucene search

K
githubGitHub Advisory DatabaseGHSA-GV98-G628-M9X5
HistoryMay 17, 2022 - 3:20 a.m.

Django Cross-site Scripting Vulnerability

2022-05-1703:20:49
CWE-79
GitHub Advisory Database
github.com
12
django
cross-site scripting
vulnerability
http
remote attackers
crafted url

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.007

Percentile

81.0%

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a \njavascript: URL.

Affected configurations

Vulners
Node
djangoRange1.71.7.3
OR
djangoRange1.61.6.10
OR
djangoRange<1.4.18
VendorProductVersionCPE
*django*cpe:2.3:a:*:django:*:*:*:*:*:*:*:*

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.007

Percentile

81.0%