mirror of
				https://github.com/django/django.git
				synced 2025-10-31 01:25:32 +00:00 
			
		
		
		
	[1.7.x] Prevented data leakage in contrib.admin via query string manipulation.
This is a security fix. Disclosure following shortly.
This commit is contained in:
		
				
					committed by
					
						 Tim Graham
						Tim Graham
					
				
			
			
				
	
			
			
			
						parent
						
							1a45d059c7
						
					
				
				
					commit
					2b31342cdf
				
			| @@ -56,6 +56,7 @@ SuspiciousOperation | ||||
|  | ||||
|     * DisallowedHost | ||||
|     * DisallowedModelAdminLookup | ||||
|     * DisallowedModelAdminToField | ||||
|     * DisallowedRedirect | ||||
|     * InvalidSessionKey | ||||
|     * SuspiciousFileOperation | ||||
|   | ||||
		Reference in New Issue
	
	Block a user