Django debug page XSS vulnerability (CVE-20
Recurrence of vulnerabilities:
1. Create a user: ip:8000/create_user/?username=alert (7)
Displays that the user has been created.
two。 Trigger vulnerability to access ip:8000/create_user/?username=alert again (7)
3. Trigger exception: duplicate key value violates unique constraint "xss_user_username_key"
DETAIL: Key (username) = (alert (7)) already exists.
4. This exception is concatenated into the The above exception ({{frame.exc_cause}}) was the direct cause of the following exception, which finally triggers XSS.