Description
Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2010-0002 | Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element. |
Github GHSA |
GHSA-7q8x-38mc-p84f | Mako contains Cross-site Scripting vulnerability |
Ubuntu USN |
USN-996-1 | Mako vulnerability |
References
History
Wed, 28 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T02:32:16.854Z
Reserved: 2010-06-28T00:00:00.000Z
Link: CVE-2010-2480
No data.
Status : Modified
Published: 2010-07-02T19:00:00.973
Modified: 2026-06-16T23:20:50.070
Link: CVE-2010-2480
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN