CVE-2011-0697Cross-site Scripting in Django

Severity
4.3MEDIUMNVD
EPSS
3.0%
top 13.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 14
Latest updateJul 23

Description

Cross-site scripting (XSS) vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 might allow remote attackers to inject arbitrary web script or HTML via a filename associated with a file upload.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

PyPIdjangoproject/django1.11.1.4+1
NVDdjangoproject/django9 versions+8

Patches

🔴Vulnerability Details

4
GHSA
Cross-site scripting in django2018-07-23
OSV
Cross-site scripting in django2018-07-23
CVEList
CVE-2011-0697: Cross-site scripting (XSS) vulnerability in Django 12011-02-14
OSV
CVE-2011-0697: Cross-site scripting (XSS) vulnerability in Django 12011-02-14

📋Vendor Advisories

2
Ubuntu
Django vulnerabilities2011-02-17
Debian
CVE-2011-0697: python-django - Cross-site scripting (XSS) vulnerability in Django 1.1.x before 1.1.4 and 1.2.x ...2011

💬Community

2
Bugzilla
CVE-2011-0696 CVE-2011-0697 Django various flaws [fedora-all]2011-02-09
Bugzilla
CVE-2011-0697 Django Potential XSS in file field rendering2011-02-09
CVE-2011-0697 — Cross-site Scripting in Django | cvebase