GHSA-x9jp-4w8m-4f3c

    Dashboard / Vulnerabilities / GHSA-x9jp-4w8m-4f3c

    GHSA-x9jp-4w8m-4f3c

    Published: 10 Jun 2022Last Modified: 7 Dec 2024

    Summary: Cross Site Scripting vulnerability in django-jsonform's admin form.

    Details: ### Description django-jsonform stores the raw JSON data of the db field in a hidden textarea on the admin page. However, that data was kept in the textarea after unescaping it using the `safe` template filter. This opens up possibilities for XSS attacks. This only affects the admin pages where the django-jsonform is rendered. ### Mitigation Upgrade to django-jsonform version 2.10.1 or later. ### For more information If you have any questions or comments about this advisory: * [Open an issue](https://github.com/bhch/django-jsonform/issues). * Email the maintainer at `Bharat Chauhan <[email protected]>`.

    Affected packages

    Package

    Name: django-jsonform

    Purl: pkg:pypi/django-jsonform

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.10.1

    Affected versions

    0.9.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-x9jp-4w8m-4f3c | CVE-DB