[arch-security] [ASA-201607-10] python-django: cross-site scripting