Description
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Email Marketing-WP Email Capture Multiple Vulnerabilities (3.9.3)
Moodle Other Vulnerability (CVE-2015-3272)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-1551)
WordPress Plugin Infusionsoft Gravity Forms Add-on Cross-Site Scripting (1.5.11)
Jenkins Improper Input Validation Vulnerability (CVE-2012-6072)