Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-25626
HistorySep 30, 2020 - 8:15 p.m.

Cross site scripting

2020-09-3020:15:00
PRIOn knowledge base
www.prio-n.com
12

6 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.4%

A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags, leading to a cross-site-scripting (XSS) vulnerability.

6 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.4%