PT-2020-5464 · Django+3 · Django+3

Published

2020-06-03

·

Updated

2026-01-03

·

CVE-2020-13596

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Django versions 2.2 before 2.2.13 Django versions 3.0 before 3.0.7
Description An issue in the Django admin ForeignKeyRawIdWidget allows for a possibility of an XSS attack due to query parameters not being properly URL encoded. This could enable a remote attacker to conduct cross-site scripting attacks. The vulnerability is related to the lack of protection measures for the web page structure, which can be exploited by a remote attacker.
Recommendations For Django versions 2.2 before 2.2.13, update to version 2.2.13 or later to resolve the issue. For Django versions 3.0 before 3.0.7, update to version 3.0.7 or later to resolve the issue. As a temporary workaround, consider disabling the ForeignKeyRawIdWidget function until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3491
BDU:2021-00719
BIT-DJANGO-2020-13596
CVE-2020-13596
DLA-2233-1
DSA-4705-1
GHSA-2M34-JCJV-45XF
OPENSUSE-SU-2024:11205-1
OPENSUSE-SU-2024:13887-1
OPENSUSE-SU-2024:14208-1
OPENSUSE-SU-2026:10005-1
PYSEC-2020-32
SUSE-RU-2020:2072-1
SUSE-RU-2020:2161-1
SUSE-SU-2020:1901-1
SUSE-SU-2020:2055-1
USN-4381-1
USN-4381-2

Affected Products

Alt Linux
Django
Linuxmint
Ubuntu