CVE-2011-0697

Django < 1.1.4 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 might allow remote attackers to inject arbitrary web script or HTML via a filename associated with a file upload.

Scores

EPSS 0.0296
EPSS Percentile 86.3%

Classification

CWE
CWE-79
Status published

Affected Products (11)

djangoproject/django
djangoproject/django
djangoproject/django
djangoproject/django
djangoproject/django
djangoproject/django
djangoproject/django
djangoproject/django
djangoproject/django
pypi/Django < 1.1.4PyPI
n/a/n/a

Timeline

Published Feb 14, 2011
Tracked Since Feb 18, 2026