Executive brief
The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.
Affected products
- PyPI django-unicorn
Junglewise Threat Intelligence
CVE-2021-42134 · Severity: low · CVSS 3.1 · Published 2021-10-11
Technologies: django-unicorn (PyPI). Vendors: PyPI.
The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.