VDB
Sign up
—

PYSEC-2020-32

Quick fix

PYSEC-2020-32 — django: upgrade to the fixed version with the command below.

pip install --upgrade 'django>=2.2.13'

Details

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django
Introduced in: 2.2Fixed in: 2.2.13
Fixpip install --upgrade 'django>=2.2.13'

References