Junglewise Threat Intelligence

CVE-2015-4706: PYSEC-2017-45 - Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vector

CVE-2015-4706 · Severity: low · CVSS 3 · Published 2017-09-21

Technologies: ipython (PyPI). Vendors: PyPI.

Executive brief

Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/contents path.

Affected products

  • PyPI ipython

Related threats