[ASA-201906-2] python-django: cross-site scripting