panel@1.6.3 vulnerabilities

The powerful data exploration & web app framework for Python.

  • latest version

    1.7.5

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    13 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the panel package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    panel is a The powerful data exploration & web app framework for Python.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to missing HTML escaping in authentication templates. The errormessage variable in the basic_login.html template and the error/error_msg variables in the error.html template fail to escape user-controlled input, allowing arbitrary script injection.

    How to fix Cross-site Scripting (XSS)?

    Upgrade panel to version 1.7.5rc0 or higher.

    [,1.7.5rc0)