Cross-Site Scripting Vulnerability in Django Framework by Django Software Foundation
CVE-2015-2317
Currently unrated
Key Information:
- Vendor
Fedoraproject
- Vendor
- CVE Published:
- 25 March 2015
What is CVE-2015-2317?
Django's utils.http.is_safe_url function prior to version 1.8c1 is susceptible to improper URL validation, which invites remote attackers to exploit this gap via malicious URLs containing control characters. This can result in cross-site scripting (XSS) attacks, a significant security risk for web applications relying on Django, allowing attackers to execute arbitrary scripts in the context of the user's browser.