Back

MEDIUM

v0.3.4): Improper escaping of single quotes in escape.cgi (XSS)

Published Jul 2, 2010

Description

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 2, 2010
Updated Aug 7, 2024
Reserved Jun 28, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jun 23, 2010
GHSA-7Q8X-38MC-P84F