{"api_version":"1","generated_at":"2026-07-23T15:32:43+00:00","cve":"CVE-2019-12308","urls":{"html":"https://cve.report/CVE-2019-12308","api":"https://cve.report/api/cve/CVE-2019-12308.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-12308","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-12308"},"summary":{"title":"CVE-2019-12308","description":"An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-06-03 17:29:00","updated_at":"2023-11-07 03:03:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://docs.djangoproject.com/en/dev/releases/security/","name":"https://docs.djangoproject.com/en/dev/releases/security/","refsource":"MISC","tags":["Vendor Advisory"],"title":"Archive of security issues | Django documentation | Django","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/USYRARSYB7PE3S2ZQO7PZNWMH7RPGL5G/","name":"FEDORA-2019-57a4324120","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 30 Update: python-django-2.1.9-1.fc30 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2019/dsa-4476","name":"DSA-4476","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4476-1 python-django","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2019/06/03/2","name":"[oss-security] 20190603 Django: CVE-2019-12308 AdminURLFieldWidget XSS (plus patched bundled jQuery for CVE-2019-11358)","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Django: CVE-2019-12308 AdminURLFieldWidget XSS (plus patched bundled\n jQuery for CVE-2019-11358)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html","name":"openSUSE-SU-2019:1839","refsource":"SUSE","tags":[],"title":"[security-announce] openSUSE-SU-2019:1839-1: moderate: Security update f","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00001.html","name":"[debian-lts-announce] 20190701 [SECURITY] [DLA 1842-1] python-django security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 1842-1] python-django security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.djangoproject.com/en/dev/releases/2.1.9/","name":"https://docs.djangoproject.com/en/dev/releases/2.1.9/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Django 2.1.9 release notes | Django documentation | Django","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2019/Jul/10","name":"20190708 [SECURITY] [DSA 4476-1] python-django security update","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: [SECURITY] [DSA 4476-1] python-django security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.djangoproject.com/en/dev/releases/1.11.21/","name":"https://docs.djangoproject.com/en/dev/releases/1.11.21/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Django 1.11.21 release notes | Django documentation | Django","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://groups.google.com/forum/#!topic/django-announce/GEbHU7YoVz8","name":"https://groups.google.com/forum/#!topic/django-announce/GEbHU7YoVz8","refsource":"MISC","tags":["Mailing List","Vendor Advisory"],"title":"Google Groups","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://usn.ubuntu.com/4043-1/","name":"USN-4043-1","refsource":"UBUNTU","tags":[],"title":"USN-4043-1: Django vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/108559","name":"108559","refsource":"BID","tags":[],"title":"Django CVE-2019-12308 Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://lists.debian.org/debian-lts-announce/2019/06/msg00001.html","name":"[debian-lts-announce] 20190605 [SECURITY] [DLA 1814-1] python-django security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 1814-1] python-django security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://groups.google.com/forum/#%21topic/django-announce/GEbHU7YoVz8","name":"https://groups.google.com/forum/#%21topic/django-announce/GEbHU7YoVz8","refsource":"","tags":[],"title":"Google Groups","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/USYRARSYB7PE3S2ZQO7PZNWMH7RPGL5G/","name":"FEDORA-2019-57a4324120","refsource":"","tags":[],"title":"[SECURITY] Fedora 30 Update: python-django-2.1.9-1.fc30 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/202004-17","name":"GLSA-202004-17","refsource":"GENTOO","tags":[],"title":"Django: Multiple vulnerabilities (GLSA 202004-17) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.djangoproject.com/weblog/2019/jun/03/security-releases/","name":"https://www.djangoproject.com/weblog/2019/jun/03/security-releases/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Django security releases issued: 2.2.2, 2.1.9 and 1.11.21 | Weblog | Django","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html","name":"openSUSE-SU-2019:1872","refsource":"SUSE","tags":[],"title":"[security-announce] openSUSE-SU-2019:1872-1: moderate: Security update f","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.djangoproject.com/en/dev/releases/2.2.2/","name":"https://docs.djangoproject.com/en/dev/releases/2.2.2/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Django 2.2.2 release notes | Django documentation | Django","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-12308","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-12308","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"12308","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"djangoproject","cpe5":"django","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"12308","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"djangoproject","cpe5":"django","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-12308","qid":"500573","title":"Alpine Linux Security Update for py3-django"},{"cve":"CVE-2019-12308","qid":"981744","title":"Python (pip) Security Update for django (GHSA-7rp2-fm2h-wchj)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-12308","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://docs.djangoproject.com/en/dev/releases/security/","refsource":"MISC","name":"https://docs.djangoproject.com/en/dev/releases/security/"},{"refsource":"MLIST","name":"[oss-security] 20190603 Django: CVE-2019-12308 AdminURLFieldWidget XSS (plus patched bundled jQuery for CVE-2019-11358)","url":"http://www.openwall.com/lists/oss-security/2019/06/03/2"},{"refsource":"MISC","name":"https://groups.google.com/forum/#!topic/django-announce/GEbHU7YoVz8","url":"https://groups.google.com/forum/#!topic/django-announce/GEbHU7YoVz8"},{"refsource":"CONFIRM","name":"https://docs.djangoproject.com/en/dev/releases/1.11.21/","url":"https://docs.djangoproject.com/en/dev/releases/1.11.21/"},{"refsource":"CONFIRM","name":"https://docs.djangoproject.com/en/dev/releases/2.1.9/","url":"https://docs.djangoproject.com/en/dev/releases/2.1.9/"},{"refsource":"CONFIRM","name":"https://docs.djangoproject.com/en/dev/releases/2.2.2/","url":"https://docs.djangoproject.com/en/dev/releases/2.2.2/"},{"refsource":"CONFIRM","name":"https://www.djangoproject.com/weblog/2019/jun/03/security-releases/","url":"https://www.djangoproject.com/weblog/2019/jun/03/security-releases/"},{"refsource":"BID","name":"108559","url":"http://www.securityfocus.com/bid/108559"},{"refsource":"MLIST","name":"[debian-lts-announce] 20190605 [SECURITY] [DLA 1814-1] python-django security update","url":"https://lists.debian.org/debian-lts-announce/2019/06/msg00001.html"},{"refsource":"FEDORA","name":"FEDORA-2019-57a4324120","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/USYRARSYB7PE3S2ZQO7PZNWMH7RPGL5G/"},{"refsource":"UBUNTU","name":"USN-4043-1","url":"https://usn.ubuntu.com/4043-1/"},{"refsource":"MLIST","name":"[debian-lts-announce] 20190701 [SECURITY] [DLA 1842-1] python-django security update","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00001.html"},{"refsource":"DEBIAN","name":"DSA-4476","url":"https://www.debian.org/security/2019/dsa-4476"},{"refsource":"BUGTRAQ","name":"20190708 [SECURITY] [DSA 4476-1] python-django security update","url":"https://seclists.org/bugtraq/2019/Jul/10"},{"refsource":"SUSE","name":"openSUSE-SU-2019:1839","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html"},{"refsource":"SUSE","name":"openSUSE-SU-2019:1872","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html"},{"refsource":"GENTOO","name":"GLSA-202004-17","url":"https://security.gentoo.org/glsa/202004-17"}]}},"nvd":{"publishedDate":"2019-06-03 17:29:00","lastModifiedDate":"2023-11-07 03:03:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*","versionStartIncluding":"2.2","versionEndExcluding":"2.2.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*","versionStartIncluding":"2.1","versionEndExcluding":"2.1.9","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*","versionStartIncluding":"1.11","versionEndExcluding":"1.11.21","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"12308","Ordinal":"150635","Title":"CVE-2019-12308","CVE":"CVE-2019-12308","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"12308","Ordinal":"1","NoteData":"An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"12308","Ordinal":"2","NoteData":"2019-06-03","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"12308","Ordinal":"3","NoteData":"2020-04-30","Type":"Other","Title":"Modified"}]}}}