PT-2020-5464 · Django+3 · Django+3
Published
2020-06-03
·
Updated
2026-01-03
·
CVE-2020-13596
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Django versions 2.2 before 2.2.13
Django versions 3.0 before 3.0.7
Description
An issue in the Django admin ForeignKeyRawIdWidget allows for a possibility of an XSS attack due to query parameters not being properly URL encoded. This could enable a remote attacker to conduct cross-site scripting attacks. The vulnerability is related to the lack of protection measures for the web page structure, which can be exploited by a remote attacker.
Recommendations
For Django versions 2.2 before 2.2.13, update to version 2.2.13 or later to resolve the issue.
For Django versions 3.0 before 3.0.7, update to version 3.0.7 or later to resolve the issue.
As a temporary workaround, consider disabling the
ForeignKeyRawIdWidget function until a patch is available.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Django
Linuxmint
Ubuntu