We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
This code prevent reflected xss attack but allow to redirect untrusted site.
django-grappelli/grappelli/views/switch.py
Lines 30 to 32 in 55f88d6
PoC http://127.0.0.1:8000/grappelli/switch/user/2/?redirect=//example.com
The text was updated successfully, but these errors were encountered:
Update switch.py
4ca94bc
This will fix issue sehmaschine#975 (I referred to this https://github.com/django/django/blob/main/django/views/i18n.py#L41-L45)
@ksg97031 thanks. just released a new version.
Sorry, something went wrong.
sehmaschine
No branches or pull requests
This code prevent reflected xss attack but allow to redirect untrusted site.
django-grappelli/grappelli/views/switch.py
Lines 30 to 32 in 55f88d6
PoC
http://127.0.0.1:8000/grappelli/switch/user/2/?redirect=//example.com
The text was updated successfully, but these errors were encountered: