mirror of
https://github.com/Hopiu/django-select2.git
synced 2026-03-20 15:20:23 +00:00
An attacker was able to use a `field_id` from a "secret" field and use if on any even the default public select2 view and receive the data without authentication. |
||
|---|---|---|
| .. | ||
| testapp | ||
| __init__.py | ||
| conftest.py | ||
| test_cache.py | ||
| test_forms.py | ||
| test_views.py | ||