PyPI: django-markdownx
CVE-2024-2319
Safety vulnerability ID: SFTY-20240308-14763
Safety legacy ID: pyup.io-66965
Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project. An attacker could store a specially crafted JavaScript payload in the upload functionality due to lack of proper sanitisation of JavaScript elements. See CVE-2024-2319.
Overview
Django MarkdownX Cross-Site Scripting (XSS) vulnerability
Advisory
Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project. An attacker could store a specially crafted JavaScript payload in the upload functionality due to lack of proper sanitisation of JavaScript elements. See CVE-2024-2319.
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20240308-14763/CVE-2024-2319
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2319
- https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerability-django-markdownx
- https://nvd.nist.gov/vuln/detail/CVE-2024-2319
- https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerability-django-markdownx
- https://github.com/advisories/GHSA-fvx8-79hx-x82f
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
