Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Django debug page XSS vulnerability (CVE-20

Shulou Source: shulou.com Published: 2022-06-01 04:19:05 10月06日 Update

Recurrence of vulnerabilities:

1. Create a user: ip:8000/create_user/?username=alert (7)

Displays that the user has been created.

two。 Trigger vulnerability to access ip:8000/create_user/?username=alert again (7)

3. Trigger exception: duplicate key value violates unique constraint "xss_user_username_key"

DETAIL: Key (username) = (alert (7)) already exists.

4. This exception is concatenated into the The above exception ({{frame.exc_cause}}) was the direct cause of the following exception, which finally triggers XSS.

Tags: Vulnerabilities users again Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Xiaomi Huawei OPPO Reno Linux Shulou Technology