CVE-2008-2302Cross-site Scripting in Django

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 36.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

PyPIdjangoproject/django0.910.91.2+2
NVDdjango_project/django0.91, 0.95, 0.96+2

Patches

🔴Vulnerability Details

4
GHSA
Django Cross-site scripting (XSS) vulnerability2022-05-01
OSV
Django Cross-site scripting (XSS) vulnerability2022-05-01
CVEList
CVE-2008-2302: Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 02008-05-23
OSV
CVE-2008-2302: Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 02008-05-23

📋Vendor Advisories

2
Red Hat
Django: administration application XSS2008-05-15
Debian
CVE-2008-2302: python-django - Cross-site scripting (XSS) vulnerability in the login form in the administration...2008

💬Community

1
Bugzilla
CVE-2008-2302 Django: administration application XSS2008-05-14
CVE-2008-2302 — Cross-site Scripting in Django | cvebase