Safety vulnerability ID: 72976
The information on this page was manually curated by our Cybersecurity Intelligence Team.
CKAN's datatables_view plugin affected versions are vulnerable to a Cross-Site Scripting (XSS) attack due to improper escaping of record data from the DataStore, allowing attackers to inject malicious scripts into tabular data previews. This issue was addressed by implementing proper HTML escaping of data within the plugin, ensuring that any potentially harmful content is neutralized before being rendered in the browser. As a precaution, administrators should prevent importing tabular files from untrusted sources until they have applied the patch.
Latest version: 2.11.2
CKAN Software
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application