CVE-2020-13596: XSS
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
Other sources
An issue was discovered in Django version 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
— GitHub
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-13596?
CVE-2020-13596 is an issue discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7 that allows for the possibility of an XSS attack.
What is the severity of CVE-2020-13596?
The severity of CVE-2020-13596 is medium with a CVSS score of 6.1.
How does CVE-2020-13596 affect Django?
CVE-2020-13596 affects Django versions 2.2 before 2.2.13 and 3.0 before 3.0.7.
How can I fix CVE-2020-13596?
To fix CVE-2020-13596, upgrade Django to version 2.2.13 or 3.0.7.
Where can I find more information about CVE-2020-13596?
You can find more information about CVE-2020-13596 on the CVE Mitre website and the Ubuntu Security Notices: USN-4381-1 and USN-4381-2.