Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. django-cms
  4. ›
  5. CVE-2024-11319

CVE-2024-11319: django CMS Cross-Site Scripting (XSS)

November 18, 2024 (updated November 20, 2024)

Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.

References

  • github.com/advisories/GHSA-gv5h-5655-h4mv
  • github.com/django-cms/django-cms
  • github.com/django-cms/django-cms/commit/241d1cbe47a68f5d271ce4d27ad5e32e2c360ec3
  • github.com/pypa/advisory-database/tree/main/vulns/django-cms/PYSEC-2024-124.yaml
  • iltosec.com/blog/post/django-cms-413-stored-xss-vulnerability-exploiting-the-page-title-field
  • nvd.nist.gov/vuln/detail/CVE-2024-11319
  • www.django-cms.org/en/blog/2024/11/13/django-cms-security-update
  • www.usom.gov.tr/bildirim/tr-24-1859

Code Behaviors & Features

Detect and mitigate CVE-2024-11319 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.11.7 before 3.11.9, all versions starting from 4.1.2 before 4.1.4

Fixed versions

  • 3.11.9
  • 4.1.4

Solution

Upgrade to versions 3.11.9, 4.1.4 or above.

Impact 4.8 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

pypi/django-cms/CVE-2024-11319.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:12 +0000.