![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2021-46898 |
Description: | views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.833790 1.3.6.1.4.1.25623.1.0.833479 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2021-46898 https://github.com/sehmaschine/django-grappelli/commit/4ca94bcda0fa2720594506853d85e00c8212968f https://github.com/sehmaschine/django-grappelli/compare/2.15.1...2.15.2 https://github.com/sehmaschine/django-grappelli/issues/975 https://github.com/sehmaschine/django-grappelli/pull/976 |