django-rest-framework@0.1.0 vulnerabilities


Direct Vulnerabilities

Known vulnerabilities in the django-rest-framework package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

django-rest-framework is an alias.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags.

How to fix Cross-site Scripting (XSS)?

There is no fixed version for django-rest-framework.