VDB
Sign up
—

PYSEC-2014-98

Quick fix

PYSEC-2014-98 — ajenti: upgrade to the fixed version with the command below.

pip install --upgrade 'ajenti>=3270fd1d78391bb847b4c9ce37cf921f485b1310'

Details

Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ajenti
Introduced in: 0Fixed in: 3270fd1d78391bb847b4c9ce37cf921f485b1310
Fixpip install --upgrade 'ajenti>=3270fd1d78391bb847b4c9ce37cf921f485b1310'

References