Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27287
HistoryOct 01, 2020 - 12:35 a.m.

Cross-site Scripting (XSS)

2020-10-0100:35:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

0.004 Low

EPSS

Percentile

72.4%

djangorestframework is vulnerable to cross-site scripting (XSS). The vulnerability exists as the use of urlize_quoted_links in rest_framework/templates/rest_framework/base.html does not sanitize `