Mako contains Cross-site Scripting vulnerability
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Sep 30, 2024
Description
Published by the National Vulnerability Database
Jul 2, 2010
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Feb 4, 2023
Last updated
Sep 30, 2024
Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.
References