CVE-2013-4249

Published: 04 October 2013

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.

Priority

Medium

Status

Package Release Status
python-django
Launchpad, Ubuntu, Debian
Upstream
Released (1.5.2-1)
Patches:
Upstream: https://github.com/django/django/commit/ec67af0bd609c412b76eaa4cc89968a2a8e5ad6a