mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 17:21:36 +00:00
80 lines
2.6 KiB
JSON
80 lines
2.6 KiB
JSON
{
|
|
"id": "CVE-2024-11404",
|
|
"sourceIdentifier": "iletisim@usom.gov.tr",
|
|
"published": "2024-11-20T12:15:18.640",
|
|
"lastModified": "2024-11-21T13:57:24.187",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Unrestricted Upload of File with Dangerous Type, Improper Input Validation, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data Manipulation, Stored XSS.This issue affects django Filer: from 3 before 3.3."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Vulnerabilidad de carga sin restricciones de archivos con tipos peligrosos, validaci\u00f3n de entrada incorrecta, neutralizaci\u00f3n incorrecta de etiquetas HTML relacionadas con scripts en una p\u00e1gina web (XSS b\u00e1sico) en Django CMS Association. Django Filer permite la manipulaci\u00f3n de datos de entrada y XSS almacenado. Este problema afecta a Django Filer: desde la versi\u00f3n 3 hasta la 3.3."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "iletisim@usom.gov.tr",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
|
|
"baseScore": 5.5,
|
|
"baseSeverity": "MEDIUM",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "LOW",
|
|
"userInteraction": "REQUIRED",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "LOW",
|
|
"integrityImpact": "LOW",
|
|
"availabilityImpact": "LOW"
|
|
},
|
|
"exploitabilityScore": 2.1,
|
|
"impactScore": 3.4
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "iletisim@usom.gov.tr",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-20"
|
|
},
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-80"
|
|
},
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-434"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://iltosec.com/blog/post/cve-2024-11404-medium-severity-file-upload-vulnerabilities-in-django-filer-323/",
|
|
"source": "iletisim@usom.gov.tr"
|
|
},
|
|
{
|
|
"url": "https://pypi.org/project/django-filer/",
|
|
"source": "iletisim@usom.gov.tr"
|
|
},
|
|
{
|
|
"url": "https://www.django-cms.org/en/blog/2024/11/19/security-updates-for-django-filer-and-django-cms-attributes-field/",
|
|
"source": "iletisim@usom.gov.tr"
|
|
},
|
|
{
|
|
"url": "https://www.usom.gov.tr/bildirim/tr-24-1864",
|
|
"source": "iletisim@usom.gov.tr"
|
|
}
|
|
]
|
|
} |