Cross-site scripting in Django - CVE-2017-7233

 

Cross-site scripting in Django - CVE-2017-7233

Published: June 16, 2017


Vulnerability identifier: #VU7105
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2017-7233
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to redirect website visitors to external websites and perform cross-site scripting (XSS) attacks.

The vulnerability is caused by incorrect filtration of input data. A remote attacker can trick the victim to follow a specially crafted link, redirect the victim on potentially dangerous website and execute arbitrary HTML and script code in victim’s browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Django
Arch Linux
Fedora
Ubuntu
py-django (Alpine package)
python-django (Red Hat package)
python-django16
python-django
Red Hat OpenStack

How to mitigate CVE-2017-7233

Update to version 1.8.18, 1.9.13, 1.10.7.

py-django (Alpine package) - update to 1.8.18-r0
python-django (Red Hat package) - update to 1.6.11-7.el7ost
python-django16 - update to 1.6.11.7-5.el7
python-django - addressed in versions 1.9.13-1.fc25, 1.10.7-1.fc26, 1.11.13-2.el7, 1.11.13-4.el7

External References

Related Security Bulletins