FreeBSD : django-cms -- XSS Vulnerability (3886cafe-668c-11e2-94b8-1c4bd681f0cf)

This script is Copyright (C) 2013 Tenable Network Security, Inc.


Synopsis :

The remote FreeBSD host is missing a security-related update.

Description :

Cross-site scripting (XSS) vulnerability

Jonas Obrist reports: The security issue allows users with limited
admin access to elevate their privileges through XSS injection using
the page_attribute template tag. Only users with admin access and the
permission to edit at least one django CMS page object could exploit
this vulnerability. Websites that do not use the page_attribute
template tag are not affected.

See also :

http://www.nessus.org/u?0216984e

Solution :

Update the affected package.

Risk factor :

High

Family: FreeBSD Local Security Checks

Nessus Plugin ID: 64089 ()

Bugtraq ID:

CVE ID:

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now