Django 1.9.8 release notesÂś
July 18, 2016
Django 1.9.8 fixes a security issue and several bugs in 1.9.7.
July 18, 2016
Django 1.9.8 fixes a security issue and several bugs in 1.9.7.
Unsafe usage of JavaScriptâs Element.innerHTML could result in XSS in the
adminâs add/change related popup. Element.textContent is now used to
prevent execution of the data.
The debug view also used innerHTML. Although a security issue wasnât
identified there, out of an abundance of caution itâs also updated to use
textContent.
Offline (Django 3.1):
HTML |
PDF |
ePub
Provided by Read the Docs.