django-ajax-utilities@1.2.8 vulnerabilities

Pagination, xhr and tabbing utilities for the Django framework.

Direct Vulnerabilities

Known vulnerabilities in the django-ajax-utilities package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

django-ajax-utilities is a Pagination, xhr and tabbing utilities for the Django framework.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Cross-site Scripting in django-ajax-utilities. A vulnerability was found in Mobile Vikings Django AJAX Utilities and classified as problematic. This issue affects the function Pagination of the file django_ajax/static/ajax-utilities/js/pagination.js of the component Backslash Handler. The manipulation of the argument url leads to cross site scripting. The attack may be initiated remotely. The patch is on commit 329eb1dd1580ca1f9d4f95bc69939833226515c9 which has been inclused in release 1.2.8. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-222611.

How to fix Cross-site Scripting (XSS)?

Upgrade django-ajax-utilities to version 1.2.9 or higher.

[,1.2.9)