Description
Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0079 | Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user. |
Github GHSA |
GHSA-hx7c-qpfq-xcrp | Cross-site Scripting in django-cms |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:25:16.860Z
Reserved: 2021-12-06T00:00:00.000Z
Link: CVE-2021-44649
No data.
Status : Modified
Published: 2022-01-12T13:15:07.737
Modified: 2024-11-21T06:31:18.960
Link: CVE-2021-44649
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA