{"id":"GHSA-x9jp-4w8m-4f3c","summary":"Cross Site Scripting vulnerability in django-jsonform's admin form.","details":"### Description\n\ndjango-jsonform stores the raw JSON data of the db field in a hidden textarea on the admin page. However, that data was kept in the textarea after unescaping it using the `safe` template filter. This opens up possibilities for XSS attacks.\n\nThis only affects the admin pages where the django-jsonform is rendered.\n\n### Mitigation\n\nUpgrade to django-jsonform version 2.10.1 or later.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* [Open an issue](https://github.com/bhch/django-jsonform/issues).\n* Email the maintainer at `Bharat Chauhan \u003ctell.bhch@gmail.com\u003e`.\n","modified":"2024-12-07T05:41:09.009182Z","published":"2022-06-10T19:51:18Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-06-10T19:51:18Z","nvd_published_at":null,"cwe_ids":["CWE-79","CWE-80"]},"references":[{"type":"WEB","url":"https://github.com/bhch/django-jsonform/security/advisories/GHSA-x9jp-4w8m-4f3c"},{"type":"PACKAGE","url":"https://github.com/bhch/django-jsonform"}],"affected":[{"package":{"name":"django-jsonform","ecosystem":"PyPI","purl":"pkg:pypi/django-jsonform"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.10.1"}]}],"versions":["0.9.0","1.0.0","2.0.0","2.1.0","2.10.0","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.6.0","2.7.0","2.8.0","2.8.1","2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-x9jp-4w8m-4f3c/GHSA-x9jp-4w8m-4f3c.json"}}],"schema_version":"1.9.0"}