Description
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin Giveaway Boost PHP Object Injection (2.1.2)
WordPress Plugin Easy Forms for MailChimp Cross-Site Scripting (6.1.2)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-31549)
WordPress Plugin OnePress Social Locker Multiple Cross-Site Scripting Vulnerabilities (4.2.0)