PT-2020-7856 · Jinja+1 · Jinja+1
Michael Scherer
·
Published
2020-02-17
·
Updated
2024-08-06
·
CVE-2015-5215
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Ipsilon versions 0.1.0 through 1.0.0
Description:
The default configuration of the Jinja templating engine in the Identity Provider (IdP) server does not enable auto-escaping, making it easier for remote attackers to conduct cross-site scripting (XSS) attacks via template variables.
Recommendations:
For Ipsilon versions 0.1.0 through 1.0.0, consider enabling auto-escaping in the Jinja templating engine configuration to mitigate the risk of cross-site scripting (XSS) attacks.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipsilon
Jinja