Executive brief
Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/notebooks path.
Affected products
- PyPI ipython
Junglewise Threat Intelligence
CVE-2015-4707 · Severity: low · CVSS 3.1 · Published 2017-09-20
Technologies: ipython (PyPI). Vendors: PyPI.
Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/notebooks path.