Lucene search

K
osvGoogleOSV:PYSEC-2021-343
HistoryAug 27, 2021 - 7:15 p.m.

PYSEC-2021-343

2021-08-2719:15:00
Google
osv.dev
14
cross site scripting
remote attack
arbitrary code execution
admin component
blogpost
mezzanine v4.3.1
cve-2018-16632

EPSS

0.001

Percentile

48.6%

Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the ‘Description’ field of the component ‘admin/blog/blogpost/add/’. This issue is different than CVE-2018-16632.

EPSS

0.001

Percentile

48.6%