Improper Input Validation Affecting django-json-widget package, versions [,2.0.0)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-DJANGOJSONWIDGET-6591325
- published 8 Apr 2024
- disclosed 1 Apr 2024
- credit Unknown
How to fix?
Upgrade django-json-widget
to version 2.0.0 or higher.
Overview
django-json-widget is a Django json widget is an alternative widget that makes it easy to edit the jsonfield field of django.
Affected versions of this package are vulnerable to Improper Input Validation due to not preventing HTML injection during the JSON handling.
References
CVSS Scores
version 3.1