Moderate severityNVD Advisory· Published Mar 8, 2024· Updated Aug 1, 2024
Cross-Site Scripting vulnerability in Django MarkdownX
CVE-2024-2319
Description
Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality due to lack of proper sanitisation of JavaScript elements.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
django-markdownxPyPI | <= 4.0.2 | — |
Affected products
2- Django MarkdownX/Django MarkdownXv5Range: 4.0.2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.