We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
This code prevent reflected xss attack but allow to redirect untrusted site.
django-grappelli/grappelli/views/switch.py
Lines 30 to 32 in 55f88d6
PoC http://127.0.0.1:8000/grappelli/switch/user/2/?redirect=//example.com
The text was updated successfully, but these errors were encountered:
Update switch.py
4ca94bc
This will fix issue sehmaschine#975 (I referred to this https://github.com/django/django/blob/main/django/views/i18n.py#L41-L45)
@ksg97031 thanks. just released a new version.
Sorry, something went wrong.
sehmaschine
No branches or pull requests
This code prevent reflected xss attack but allow to redirect untrusted site.
django-grappelli/grappelli/views/switch.py
Lines 30 to 32 in 55f88d6
PoC
http://127.0.0.1:8000/grappelli/switch/user/2/?redirect=//example.com
The text was updated successfully, but these errors were encountered: