Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2020-13596
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.011
EPSS Ranking
76.7%
CVSS Severity
CVSS v3 Score
6.1
CVSS v2 Score
4.3
References
https://docs.djangoproject.com/en/3.0/releases/security/
https://groups.google.com/forum/#%21msg/django-announce/pPEmb2ot4Fo/X-SMalYSBAAJ
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4A2AP4T7RKPBCLTI2NNQG3T6MINDUUMZ/
https://security.netapp.com/advisory/ntap-20200611-0002/
https://usn.ubuntu.com/4381-1/
https://usn.ubuntu.com/4381-2/
https://www.debian.org/security/2020/dsa-4705
https://www.djangoproject.com/weblog/2020/jun/03/security-releases/
https://www.oracle.com/security-alerts/cpujan2021.html
https://docs.djangoproject.com/en/3.0/releases/security/
https://groups.google.com/forum/#%21msg/django-announce/pPEmb2ot4Fo/X-SMalYSBAAJ
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4A2AP4T7RKPBCLTI2NNQG3T6MINDUUMZ/
https://security.netapp.com/advisory/ntap-20200611-0002/
https://usn.ubuntu.com/4381-1/
https://usn.ubuntu.com/4381-2/
https://www.debian.org/security/2020/dsa-4705
https://www.djangoproject.com/weblog/2020/jun/03/security-releases/
https://www.oracle.com/security-alerts/cpujan2021.html
Products affected by CVE-2020-13596
Djangoproject
»
Django
»
Version:
2.2
cpe:2.3:a:djangoproject:django:2.2
Djangoproject
»
Django
»
Version:
2.2.1
cpe:2.3:a:djangoproject:django:2.2.1
Djangoproject
»
Django
»
Version:
2.2.10
cpe:2.3:a:djangoproject:django:2.2.10
Djangoproject
»
Django
»
Version:
2.2.11
cpe:2.3:a:djangoproject:django:2.2.11
Djangoproject
»
Django
»
Version:
2.2.2
cpe:2.3:a:djangoproject:django:2.2.2
Djangoproject
»
Django
»
Version:
2.2.3
cpe:2.3:a:djangoproject:django:2.2.3
Djangoproject
»
Django
»
Version:
2.2.4
cpe:2.3:a:djangoproject:django:2.2.4
Djangoproject
»
Django
»
Version:
2.2.5
cpe:2.3:a:djangoproject:django:2.2.5
Djangoproject
»
Django
»
Version:
2.2.6
cpe:2.3:a:djangoproject:django:2.2.6
Djangoproject
»
Django
»
Version:
2.2.7
cpe:2.3:a:djangoproject:django:2.2.7
Djangoproject
»
Django
»
Version:
2.2.8
cpe:2.3:a:djangoproject:django:2.2.8
Djangoproject
»
Django
»
Version:
2.2.9
cpe:2.3:a:djangoproject:django:2.2.9
Djangoproject
»
Django
»
Version:
3.0
cpe:2.3:a:djangoproject:django:3.0
Djangoproject
»
Django
»
Version:
3.0.1
cpe:2.3:a:djangoproject:django:3.0.1
Djangoproject
»
Django
»
Version:
3.0.2
cpe:2.3:a:djangoproject:django:3.0.2
Djangoproject
»
Django
»
Version:
3.0.3
cpe:2.3:a:djangoproject:django:3.0.3
Djangoproject
»
Django
»
Version:
3.0.4
cpe:2.3:a:djangoproject:django:3.0.4
Djangoproject
»
Django
»
Version:
3.0.5
cpe:2.3:a:djangoproject:django:3.0.5
Djangoproject
»
Django
»
Version:
3.0.6
cpe:2.3:a:djangoproject:django:3.0.6
Netapp
»
Sra Plugin
»
Version:
N/A
cpe:2.3:a:netapp:sra_plugin:-
Netapp
»
Steelstore Cloud Integrated Storage
»
Version:
N/A
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-
Oracle
»
Zfs Storage Appliance Kit
»
Version:
8.8
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8
Canonical
»
Ubuntu Linux
»
Version:
14.04
cpe:2.3:o:canonical:ubuntu_linux:14.04
Canonical
»
Ubuntu Linux
»
Version:
16.04
cpe:2.3:o:canonical:ubuntu_linux:16.04
Canonical
»
Ubuntu Linux
»
Version:
18.04
cpe:2.3:o:canonical:ubuntu_linux:18.04
Canonical
»
Ubuntu Linux
»
Version:
19.10
cpe:2.3:o:canonical:ubuntu_linux:19.10
Canonical
»
Ubuntu Linux
»
Version:
20.04
cpe:2.3:o:canonical:ubuntu_linux:20.04
Debian
»
Debian Linux
»
Version:
10.0
cpe:2.3:o:debian:debian_linux:10.0
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Fedoraproject
»
Fedora
»
Version:
32
cpe:2.3:o:fedoraproject:fedora:32
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved