CVE-2021-46898

MEDIUM

Django Grappelli <2.15.2 - Open Redirect

Title source: llm
STIX 2.1

Description

views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack.

Scores

CVSS v3 6.1
EPSS 0.0047
EPSS Percentile 37.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
pypi/django-grappelli 0 - 2.15.2PyPI
vonautomatisch/django_grappelli < 2.15.2
Published Oct 22, 2023
Tracked Since Feb 18, 2026