Safety vulnerability ID: 78742
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the django-tinymce package are vulnerable to Cross-site Scripting due to improper parsing of `noscript` content. The content parsing module fails to neutralize potentially malicious code embedded within `noscript` elements, allowing execution of unescaped input when loaded into the django-tinymce editor. An attacker can embed crafted `noscript` content in user-supplied input—such as HTML loaded into the editor—resulting in script execution in the editor’s context, which may lead to session hijacking, cookie theft, or other client-side compromise.
Latest version: 4.1.0
A Django application that contains a widget to render a
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application