Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:49
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.8 |
20 Nov 2024, 14:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/django-cms/django-cms/commit/241d1cbe47a68f5d271ce4d27ad5e32e2c360ec3 - Patch | |
References | () https://iltosec.com/blog/post/django-cms-413-stored-xss-vulnerability-exploiting-the-page-title-field/ - Exploit | |
References | () https://www.django-cms.org/en/blog/2024/11/13/django-cms-security-update/ - Vendor Advisory | |
References | () https://www.usom.gov.tr/bildirim/tr-24-1859 - Third Party Advisory | |
First Time |
Django-cms
Django-cms django Cms |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
CPE | cpe:2.3:a:django-cms:django_cms:4.1.3:*:*:*:*:*:*:* cpe:2.3:a:django-cms:django_cms:4.1.2:*:*:*:*:*:*:* cpe:2.3:a:django-cms:django_cms:3.11.8:*:*:*:*:*:*:* cpe:2.3:a:django-cms:django_cms:3.11.7:*:*:*:*:*:*:* |
20 Nov 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.8 |
18 Nov 2024, 17:11
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
18 Nov 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.6 |
18 Nov 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-18 12:15
Updated : 2024-11-21 08:49
NVD link : CVE-2024-11319
Mitre link : CVE-2024-11319
CVE.ORG link : CVE-2024-11319
JSON object : View
Products Affected
django-cms
- django_cms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')