Description
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
Remediation
References
Related Vulnerabilities
PrestaShop Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-20717)
WordPress Plugin Filter Custom Fields & Taxonomies Light Unspecified Vulnerability (1.04)
Liferay Portal Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2025-43816)
Oracle Database Server CVE-2015-0371 Vulnerability (CVE-2015-0371)