CVE-2010-3082

Django <1.2.2 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Django 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via a csrfmiddlewaretoken (aka csrf_token) cookie.

Scores

EPSS 0.0041
EPSS Percentile 60.8%

Classification

CWE
CWE-79
Status published

Affected Products (5)

djangoproject/django
djangoproject/django
djangoproject/django
pypi/Django < 1.2.2PyPI
n/a/n/a

Timeline

Published Sep 14, 2010
Tracked Since Feb 18, 2026