Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 PyPI

Django Cross-site Scripting Vulnerability

GHSA-gv98-g628-m9x5 · CVE-2015-0220 · PYSEC-2015-5

Published · Modified

Description

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a \njavascript: URL.

Ready to move

Start Securing

Free, no credit card | First findings in minutes