django-widgy@0.8.3 vulnerabilities

A CMS framework for Django built on a heterogenous tree editor.

  • latest version

    0.9.2

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    3 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the django-widgy package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Arbitrary File Upload

    django-widgy is an A CMS framework for Django built on a heterogenous tree editor.

    Affected versions of this package are vulnerable to Arbitrary File Upload. This allows attackers to execute arbitrary code via the image widget in the component Change Widgy Page.

    How to fix Arbitrary File Upload?

    Upgrade django-widgy to version 0.9.0 or higher.

    [,0.9.0)