Cross-site scripting in Django - CVE-2017-7233

 

Cross-site scripting in Django - CVE-2017-7233

Published: June 16, 2017


Vulnerability identifier: #VU7105
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-7233
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Django Software Foundation
Affected software:
Django

Detailed vulnerability description

The disclosed vulnerability allows a remote attacker to redirect website visitors to external websites and perform cross-site scripting (XSS) attacks.

The vulnerability is caused by incorrect filtration of input data. A remote attacker can trick the victim to follow a specially crafted link, redirect the victim on potentially dangerous website and execute arbitrary HTML and script code in victim’s browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


How to mitigate CVE-2017-7233

Update to version 1.8.18, 1.9.13, 1.10.7.

Sources