CVE-2010-3082Cross-site Scripting in Django

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 38.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 14
Latest updateJul 23

Description

Cross-site scripting (XSS) vulnerability in Django 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via a csrfmiddlewaretoken (aka csrf_token) cookie.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

PyPIdjangoproject/django1.21.2.2
NVDdjangoproject/django1.2.1, 1.2.2+1

Patches

🔴Vulnerability Details

4
OSV
Cross-site scripting in django2018-07-23
GHSA
Cross-site scripting in django2018-07-23
OSV
CVE-2010-3082: Cross-site scripting (XSS) vulnerability in Django 12010-09-14
CVEList
CVE-2010-3082: Cross-site scripting (XSS) vulnerability in Django 12010-09-14

📋Vendor Advisories

2
Ubuntu
Django vulnerability2010-10-13
Debian
CVE-2010-3082: python-django - Cross-site scripting (XSS) vulnerability in Django 1.2.x before 1.2.2 allows rem...2010

💬Community

2
Bugzilla
CVE-2010-3082 Django CSRF flaw2010-09-09
Bugzilla
CVE-2010-3082 Django CSRF flaw [fedora-all]2010-09-09
CVE-2010-3082 — Cross-site Scripting in Django | cvebase