Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Django-wiki - Stored Cross-Site Scripting (XSS) in Notifications Section
Vulnerability Description
In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the notification panel renders and loads external JavaScript.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Django 跨站脚本漏洞
Vulnerability Description
Django是Django基金会的一套基于Python语言的开源Web应用框架。该框架包括面向对象的映射器、视图系统、模板系统等。 Django wiki 中存在安全漏洞,有权访问编辑页面的攻击者可以在标题字段中注入 JavaScript 负载。当受害者收到有关应用程序更改的通知时,通知面板中的有效负载会呈现并加载外部 JavaScript。
CVSS Information
N/A
Vulnerability Type
N/A