Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Charles Bideau

#42203of 53,632
6.4Total CVSS
Vulnerabilities · 1
PT-2017-3841
6.4
2017-09-05
Django · Django · CVE-2017-12794
**Name of the Vulnerable Software and Affected Versions** Django versions 1.10.x through 1.10.7 Django versions 1.11.x through 1.11.4 **Description** The issue is related to the disabling of HTML autoescaping in a portion of the template for the technical 500 debug page in Django. This could allow a cross-site scripting attack under the right circumstances. The vulnerability is unlikely to affect most production sites, as they should not be run with `DEBUG = True`, which makes the debug page accessible. **Recommendations** For Django versions 1.10.x through 1.10.7, update to version 1.10.8 or later. For Django versions 1.11.x through 1.11.4, update to version 1.11.5 or later. As a temporary workaround, consider setting `DEBUG = False` in production settings to minimize the risk of exploitation.