VDB
KO
MEDIUM 4.8

PYSEC-2024-124

Details

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / django-cms
Introduced in: 0 Fixed in: 241d1cbe47a68f5d271ce4d27ad5e32e2c360ec3
Fix pip install --upgrade 'django-cms>=241d1cbe47a68f5d271ce4d27ad5e32e2c360ec3'

References