First published: Thu Mar 12 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the contents function in `admin/helpers.py` in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in `ModelAdmin.readonly_fields`, as demonstrated by an `@property`.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/django | <1.7.6 | 1.7.6 |
pip/django | >=1.8a1<1.8b2 | 1.8b2 |
Djangoproject Django | <=1.7.5 | |
Djangoproject Django | =1.8-beta1 | |
<=1.7.5 | ||
=1.8-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.