Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-31047
Description:In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.
Test IDs: 1.3.6.1.4.1.25623.1.0.126326   1.3.6.1.4.1.25623.1.1.12.2023.6054.1   1.3.6.1.4.1.25623.1.0.827702   1.3.6.1.4.1.25623.1.1.1.1.2023.5465   1.3.6.1.4.1.25623.1.0.827675   1.3.6.1.4.1.25623.1.0.126363   1.3.6.1.4.1.25623.1.1.1.2.2023.3415   1.3.6.1.4.1.25623.1.1.12.2023.6054.2  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-31047
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A45VKTUVQ2BN6D5ZLZGCM774R6QGFOHW/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DNEHD6N435OE2XUFGDAAVAXSYWLCUBFD/
https://docs.djangoproject.com/en/4.2/releases/security/
https://groups.google.com/forum/#!forum/django-announce




© 1998-2025 E-Soft Inc. All rights reserved.