Django Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-6044 - Vulnerability Database

Django Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-6044

Medium
Reference: CVE-2013-6044
Title: Django Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6 1.5.x before 1.5.2 and 1.6 before beta 2 treats a URL39s scheme as safe even if it is not HTTP or HTTPS which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function as demonstrated by quotthe login view in django.contrib.auth.viewsquot and the javascript: scheme.