QID 981744
QID 981744: Python (pip) Security Update for django (GHSA-7rp2-fm2h-wchj)
An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7rp2-fm2h-wchj for updates pertaining to this vulnerability.
Vendor References
- GHSA-7rp2-fm2h-wchj -
github.com/advisories/GHSA-7rp2-fm2h-wchj
CVEs related to QID 981744
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7rp2-fm2h-wchj | django |
|