CVE-2024-2319

All FrameworksDjangoCWE-79CVE-2024-2319

CVE-2024-2319

State: PUBLISHED · Published: 2024-03-08 · Updated: 2024-08-01 · Assigner: INCIBE
Description
Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality due to lack of proper sanitisation of JavaScript elements.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2024/2xxx/CVE-2024-2319.json