Cross-site Scripting in django-cms
Moderate severity
GitHub Reviewed
Published
Jan 13, 2022
to the GitHub Advisory Database
•
Updated Sep 16, 2024
Package
Affected versions
>= 3.7.0, < 3.7.4
>= 3.6.0, < 3.6.1
>= 3.5.0, < 3.5.4
>= 3.4.0, < 3.4.7
Patched versions
3.7.4
3.6.1
3.5.4
3.4.7
Description
Published by the National Vulnerability Database
Jan 12, 2022
Reviewed
Jan 13, 2022
Published to the GitHub Advisory Database
Jan 13, 2022
Last updated
Sep 16, 2024
Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.
References