[arch-security] [ASA-201607-11] python2-django: cross-site scripting