Description
The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
Remediation
References
Related Vulnerabilities
Mailman Other Vulnerability (CVE-2002-0389)
WordPress Cross-Site Scripting Vulnerability (0.70 - 4.1.1)
WordPress Plugin IBPS Online Exam Multiple Vulnerabilities (1.0)
WordPress Plugin MyBookTable Bookstore by Author Media Cross-Site Scripting (3.2.1)
Oracle Application Server Other Vulnerability (CVE-2006-5355)