VYPR
Moderate severityNVD Advisory· Published Mar 8, 2024· Updated Aug 1, 2024

Cross-Site Scripting vulnerability in Django MarkdownX

CVE-2024-2319

Description

Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality due to lack of proper sanitisation of JavaScript elements.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
django-markdownxPyPI
<= 4.0.2

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.