QID 981432
QID 981432: Python (pip) Security Update for django-widgy (GHSA-98hv-qff3-8793)
Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-98hv-qff3-8793 for updates pertaining to this vulnerability.
Vendor References
- GHSA-98hv-qff3-8793 -
github.com/advisories/GHSA-98hv-qff3-8793
CVEs related to QID 981432
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-98hv-qff3-8793 | django-widgy |
|