Security Advisory

CVE-2020-13596

6.1
MEDIUM

Vulnerability Description

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
Published Date June 3, 2020
Official Source NIST NVD Advisory