—
PYSEC-2014-98
Quick fix
PYSEC-2014-98 — ajenti: upgrade to the fixed version with the command below.
pip install --upgrade 'ajenti>=3270fd1d78391bb847b4c9ce37cf921f485b1310'Details
Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/ajenti
Introduced in:
0Fixed in: 3270fd1d78391bb847b4c9ce37cf921f485b1310Fix
pip install --upgrade 'ajenti>=3270fd1d78391bb847b4c9ce37cf921f485b1310'References
- http://www.securityfocus.com/bid/64982[WEB]
- https://github.com/Eugeny/ajenti/commit/3270fd1d78391bb847b4c9ce37cf921f485b1310[FIX]
- http://www.osvdb.org/102174[WEB]
- http://packetstormsecurity.com/files/124804/Ajenti-1.2.13-Cross-Site-Scripting.html[WEB]
- https://github.com/Eugeny/ajenti/issues/233[REPORT]
- https://github.com/advisories/GHSA-9crx-p357-5vw8[ADVISORY]