CVE-2024-11404

Unrestricted Upload of File with Dangerous Type, Improper Input Validation, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data Manipulation, Stored XSS.This issue affects django Filer: from 3 before 3.3.
Configurations

No configuration.

History

20 Nov 2024, 14:15

Type Values Removed Values Added
References
  • {'url': 'https://iltosec.com/blog/post/djangocms-attributes-field-300-stored-xss-vulnerability/', 'source': 'iletisim@usom.gov.tr'}
  • () https://iltosec.com/blog/post/cve-2024-11404-medium-severity-file-upload-vulnerabilities-in-django-filer-323/ -

20 Nov 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-20 12:15

Updated : 2024-11-20 14:15


NVD link : CVE-2024-11404

Mitre link : CVE-2024-11404

CVE.ORG link : CVE-2024-11404


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)