Back

HIGH

python-werkzeug: Cross-site scripting in render_full function in debug/tbtools.py

Published Oct 23, 2017

Description

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 23, 2017
Updated Aug 6, 2024
Reserved Oct 23, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 23, 2017
GHSA-H2FP-XGX6-XH6F