LWN.net Logo

python-django: cross-site scripting

Package(s):python-django CVE #(s):CVE-2013-4249
Created:August 23, 2013 Updated:September 3, 2013
Description:

From the Red Hat bugzilla entry:

When displaying the value of a URLField -- a model field type for storing URLs -- this interface treated the values of such fields as safe, thus failing to properly accommodate the potential for dangerous values. A proof-of-concept application has been provided to the Django project, showing how this can be exploited to perform XSS in the administrative interface.

In a normal Django deployment, this will only affect the administrative interface, as the incorrect handling occurs only in form-widget code in django.contrib.admin. It is, however, possible that other applications may be affected, if those applications make use of form widgets provided by the admin interface.

Alerts:
Fedora FEDORA-2013-14797 2013-08-23
Mageia MGASA-2013-0256 2013-08-22
Mandriva MDVSA-2013:218 2013-08-23
Debian DSA-2740-1 2013-08-23
Fedora FEDORA-2013-14852 2013-08-27
Debian DSA-2740-2 2013-09-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds