Django 1.2.2 released to close XSS enabling hole

16

Django 1.2.x users are “urged to upgrade immediately” to version 1.2.2 as a flaw in cross site request forgery protection enables XSS attacks

Read more at The H