Impact
djust renders a developer or user supplied URL into an anchor or form attribute using conditional escaping, but does not validate the URL scheme. The escape mitigates attribute breakout but simply a javascript: URI bypasses the reach of escaping, allowing the URI to be inserted verbatim into an href or action attribute. When the victim clicks the link, the browser interprets the URI as a script and runs it in the context of the application, providing an attacker with the ability to read session cookies, deface pages, or launch further attacks. The weakness is a classic example of client‑side injection (CWE‑79).
Affected Systems
This flaw appears in the djust framework for Django, in all installed versions of djust-org:djust released before v1.0.7. The fix was introduced in release 1.0.7 and later. No other vendors or products are mentioned as affected.
Risk and Exploitability
The severity of the flaw is assessed with a CVSS score of 5.1, indicating a medium likelihood of impact. The EPSS score is reported as less than 1%, suggesting a low probability of actual exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploit in the wild. Attackers could deliver the malicious URL through the built‑in component tags by supplying user‑controlled input; the flaw can be both reflected and stored, depending on how the application uses the tags. An attacker would need to place the malicious URL in an instance of the template tag’s arguments and then lure a user to click the resulting link. Fairly simple in practice, this requires only that the attacker control the component argument value, making the vector relatively straightforward for applications that expose these tags to arbitrary input.
OpenCVE Enrichment
Github GHSA