{"id":"PYSEC-2010-12","details":"Cross-site scripting (XSS) vulnerability in Django 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via a csrfmiddlewaretoken (aka csrf_token) cookie.","aliases":["CVE-2010-3082","GHSA-fxpg-gg9g-76gj"],"modified":"2023-11-08T03:56:56.942182Z","published":"2010-09-14T19:00:00Z","references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=632239"},{"type":"WEB","url":"http://marc.info/?l=oss-security&m=128403961700444&w=2"},{"type":"ARTICLE","url":"http://www.djangoproject.com/weblog/2010/sep/08/security-release/"},{"type":"WEB","url":"http://www.securityfocus.com/bid/43116"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1004-1"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/61729"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fxpg-gg9g-76gj"}],"affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2"},{"fixed":"1.2.2"}]}],"versions":["1.2","1.2.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2010-12.yaml"}}],"schema_version":"1.7.3"}