{"id":"GHSA-x9jp-4w8m-4f3c","aliases":[],"url":"https://o3.security/vulnerability/GHSA-x9jp-4w8m-4f3c","summary":"Cross Site Scripting vulnerability in django-jsonform's admin form.","details":"### Description\n\ndjango-jsonform stores the raw JSON data of the db field in a hidden textarea on the admin page. However, that data was kept in the textarea after unescaping it using the `safe` template filter. This opens up possibilities for XSS attacks.\n\nThis only affects the admin pages where the django-jsonform is rendered.\n\n### Mitigation\n\nUpgrade to django-jsonform version 2.10.1 or later.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* [Open an issue](https://github.com/bhch/django-jsonform/issues).\n* Email the maintainer at `Bharat Chauhan <tell.bhch@gmail.com>`.\n","published":"2022-06-10T19:51:18Z","modified":"2024-12-07T05:41:09.009182Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"django-jsonform","fixedVersion":"2.10.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/bhch/django-jsonform/security/advisories/GHSA-x9jp-4w8m-4f3c"},{"type":"PACKAGE","url":"https://github.com/bhch/django-jsonform"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-07T05:41:09.009182Z"}}