mirror of
https://github.com/Hopiu/django-select2.git
synced 2026-03-26 18:00:25 +00:00
An attacker was able to use a `field_id` from a "secret" field and use if on any even the default public select2 view and receive the data without authentication. |
||
|---|---|---|
| .. | ||
| static/django_select2 | ||
| __init__.py | ||
| cache.py | ||
| conf.py | ||
| forms.py | ||
| models.py | ||
| urls.py | ||
| views.py | ||