CVE-2009-4924

python-cjson < 1.1.0 - Cross-Site Scripting via cjson.encode Function

Title source: llm
STIX 2.1

Description

Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.

References (2)

Core 2
Core References
Various Sources x_refsource_misc
http://pypi.python.org/pypi/python-cjson/

Scores

EPSS 0.0135
EPSS Percentile 68.7%

Details

CWE
CWE-79
Status published
Products (2)
dan_pascu/python-cjson 1.0.5
pypi/python-cjson 0 - 1.1.0PyPI
Published Jul 02, 2010
Tracked Since Feb 18, 2026