Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality due to lack of proper sanitisation of JavaScript elements.

Project Subscriptions

Vendors Products
Neutronx Subscribe
Markdownx Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0924 Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality due to lack of proper sanitisation of JavaScript elements.
Github GHSA Github GHSA GHSA-fvx8-79hx-x82f Django MarkdownX Cross-Site Scripting (XSS) vulnerability
Fixes

Solution

There is no reported solution at this time.


Workaround

No workaround given by the vendor.

History

Wed, 26 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Neutronx
Neutronx markdownx
CPEs cpe:2.3:a:neutronx:markdownx:4.0.2:*:*:*:*:django:*:*
Vendors & Products Neutronx
Neutronx markdownx

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T19:11:52.461Z

Reserved: 2024-03-08T08:11:13.548Z

Link: CVE-2024-2319

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:52.461Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-08T14:15:52.307

Modified: 2025-02-26T15:14:55.753

Link: CVE-2024-2319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses