Pallets · Werkzeug · CVE-2016-10516
**Name of the Vulnerable Software and Affected Versions**
Werkzeug versions prior to 0.11.11
**Description**
A cross-site scripting (XSS) issue exists in the render full function in debug/tbtools.py in the debugger, allowing remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.
**Recommendations**
For versions prior to 0.11.11, update to version 0.11.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the debugger to minimize the risk of exploitation.