Description
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2001-1385)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-9546)
WordPress Plugin Blog social sharing component Cross-Site Request Forgery (1.4.5)
WordPress Plugin WP Sitemap Page Cross-Site Scripting (1.6.4)
Oracle Application Server Other Vulnerability (CVE-2007-0222)