Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.
Software | From | Fixed in |
---|---|---|
debian / debian_linux | 8.0 | 8.0.x |
djangoproject / django | 1.10-alpha1 | 1.10-alpha1.x |
djangoproject / django | 1.9.6 | 1.9.6.x |
djangoproject / django | 1.9.0-rc1 | 1.9.0-rc1.x |
djangoproject / django | 1.9.5 | 1.9.5.x |
djangoproject / django | - | 1.8.13.x |
djangoproject / django | 1.9.3 | 1.9.3.x |
djangoproject / django | 1.9.4 | 1.9.4.x |
djangoproject / django | 1.9.7 | 1.9.7.x |
djangoproject / django | 1.9.1 | 1.9.1.x |
djangoproject / django | 1.9 | 1.9.x |
djangoproject / django | 1.10-beta1 | 1.10-beta1.x |
djangoproject / django | 1.9.2 | 1.9.2.x |