CVE-2021-44649
MEDIUMdjango-cms 3.4.0-3.4.6 and 3.7.0-3.7.3 - Cross-Site Scripting via Plugin Type Parameter
Title source: llmDescription
Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://sahildhar.github.io/blogpost/Django-CMS-Reflected-XSS-Vulnerability/
Vendor Advisory x_refsource_misc
https://www.django-cms.org/en/blog/2020/07/22/django-cms-security-updates-1/
Scores
CVSS v3
5.4
EPSS
0.0062
EPSS Percentile
45.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
django-cms/django_cms
3.4.0 - 3.4.7
pypi/django-cms
3.7.0 - 3.7.4PyPI
Published
Jan 12, 2022
Tracked Since
Feb 18, 2026