PT-2021-10218 · Unknown · Django-Widgy

Hatboy

·

Published

2021-08-16

·

Updated

2021-08-30

·

CVE-2020-18704

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Django-Widgy version 0.8.4
Description: The issue allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'. This is due to an unrestricted upload of files with dangerous types.
Recommendations: For Django-Widgy version 0.8.4, consider disabling the 'image' widget in the 'Change Widgy Page' component until a patch is available to prevent remote attackers from executing arbitrary code. Restrict access to file uploads to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-18704
GHSA-98HV-QFF3-8793
PYSEC-2021-336

Affected Products

Django-Widgy