Junglewise Threat Intelligence

CVE-2021-44649: PYSEC-2022-7 - Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cros

CVE-2021-44649 · Severity: low · CVSS 3.1 · Published 2022-01-12

Technologies: django-cms (PyPI). Vendors: PyPI.

Executive brief

Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.

Affected products

  • PyPI django-cms

Related threats