#2152 closed defect (fixed)
[patch] Username is not escaped in django admin
| Reported by: | Owned by: | Adrian Holovaty | |
|---|---|---|---|
| Component: | contrib.admin | Version: | |
| Severity: | normal | Keywords: | |
| Cc: | Sergey Kirillov <rushman@…> | Triage Stage: | Unreviewed |
| Has patch: | yes | Needs documentation: | no |
| Needs tests: | no | Patch needs improvement: | no |
| Easy pickings: | no | UI/UX: | no |
Description
If you set your user first name to '<script>alert(1)</script>' you will get JS alert for each django admin page.
Attachments (1)
Note:
See TracTickets
for help on using tickets.
patch