Lucene search

K
redhatcveRedhat.comRH:CVE-2019-12308
HistoryApr 09, 2020 - 10:36 a.m.

CVE-2019-12308

2020-04-0910:36:35
redhat.com
access.redhat.com
10

0.01 Low

EPSS

Percentile

84.0%

A validation flaw was found in Django’s AdminURLFieldWidget. The clickable Current URL link generated by AdminURLFieldWidget displayed the provided value without validating it as a safe URL. An unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in a clickable JavaScript link.