There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://morningchen.com/2017/03/09/Cross-site-scripting-vulnerability-in-django-epiceditor/ | exploit third party advisory technical description |
http://www.securityfocus.com/bid/96946 | vdb entry |