PT-2024-9176 · Unknown · Django Cms

Ali Iltizar

+1

·

Published

2024-11-13

·

Updated

2024-11-20

·

CVE-2024-11319

CVSS v4.0

9.3

Critical

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: django-cms versions 3.11.7 through 3.11.8 django-cms versions 4.1.2 through 4.1.3
Description: The issue is related to improper neutralization of input during web page generation, allowing Cross-Site Scripting (XSS). This can be exploited by a remote attacker to conduct an XSS attack. The vulnerability is associated with the failure to protect the structure of web pages. Technical details include the exploitation of the Page Title field in the Page Creation interface, allowing JavaScript injection.
Recommendations: For django-cms versions 3.11.7 and 3.11.8, update to a version that includes the fix for this issue. For django-cms versions 4.1.2 and 4.1.3, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Page Creation interface to minimize the risk of exploitation. Avoid using the Page Title field in the affected versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-10863
CVE-2024-11319
GHSA-GV5H-5655-H4MV

Affected Products

Django Cms