Release | February 13, 2013

2.3.5 Security release

We just issued a security release for django CMS 2.3. All versions are affected and users are encouraged to upgrade immediately.

5 minutes read

The security issue fixed in this release allowed users with limited admin access to elevate their privileges through XSS injection using the page_attribute template tag. Only users with admin access and the permission to edit at least one django CMS page object could exploit this vulnerability. Websites that do not use the page_attribute template tag are not affected.

Full list of changes in this release

  • Output of page_attribute template tag is escaped.

Affected versions

  • All versions are affected

Affected APIs

  • The vulnerability is in the page_attribute template tag. Only websites using this template tag are vulnerable.

General note regarding security reporting

Please report any potential security issues via private email to [email protected], and not via a public channel such as our IRC channel, our mailinglists or our bug tracker.

Article

One operation, three interfaces: a service architecture for django CMS

How shared content operations could support editors, REST integrations, and AI tools.

Release

django CMS 5.1.3 and 5.0.13 released

We’re pleased to announce the release of django CMS 5.1.3 and django CMS 5.0.13. Both are maintenance releases focused on fixes and improved robustness.

Community news

Inside the Work That Moves django CMS Forward

As the django CMS fellows, we have spent this year so far strengthening that foundation and making new capabilities available to developers and editors.