Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://huntr.dev/bounties/47f08086-aaae-4ca7-b0ca-24c616d3ad7d | patch exploit third party advisory issue tracking |
https://github.com/liangliangyy/djangoblog/commit/c2bfdb18c5f32b13ea4b50aa689b8ea4beb38719 | patch |