CVE-2021-44649
Dashboard / Vulnerabilities / CVE-2021-44649
CVE-2021-44649
Published: 12 Jan 2022Last Modified: 8 Jul 2026
Aliases:
Summary:
Details: Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.
References: https://www.django-cms.org/en/blog/2020/07/22/django-cms-security-updates-1/, https://sahildhar.github.io/blogpost/Django-CMS-Reflected-XSS-Vulnerability/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 4e2ac3e73845fa0a2970247996ddd6fe16408fc0
Affected versions
3.7.3
3.7.2
3.7.1
3.7.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
