Skip to content

Commit

Permalink
[4.2.x] Added warning about flatpages and untrusted users.
Browse files Browse the repository at this point in the history
Backport of 571bab9 from main
  • Loading branch information
felixxm committed Sep 27, 2023
1 parent fec4ed0 commit dd0bf63
Showing 1 changed file with 7 additions and 0 deletions.
7 changes: 7 additions & 0 deletions docs/ref/contrib/flatpages.txt
Original file line number Diff line number Diff line change
Expand Up @@ -164,6 +164,13 @@ For more on middleware, read the :doc:`middleware docs
How to add, change and delete flatpages
=======================================

.. warning::

Permissions to add or edit flatpages should be restricted to trusted users.
Flatpages are defined by raw HTML and are **not sanitized** by Django. As a
consequence, a malicious flatpage can lead to various security
vulnerabilities, including permission escalation.

.. _flatpages-admin:

Via the admin interface
Expand Down

0 comments on commit dd0bf63

Please sign in to comment.