CVE-2018-25045

Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.
Configurations

Configuration 1 (hide)

cpe:2.3:a:django-rest-framework:django_rest_framework:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-07-23 02:15

Updated : 2024-02-28 19:29


NVD link : CVE-2018-25045

Mitre link : CVE-2018-25045

CVE.ORG link : CVE-2018-25045


JSON object : View

Products Affected

django-rest-framework

  • django_rest_framework
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')