← Back

CVE-2023-31047

nvd nist
Published: May 7, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.

Affected (6)

1 product
Django
1 product
Fedora
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
From 3.2 to 3.2.19
From 4.0 to 4.1.9
Version 4.2
Version 4.2 b1
Version 4.2 rc1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 38

Timeline

No history available yet.