springload / madewithwagtail

A showcase of sites and apps made with Wagtail CMS, the easy to use, open source Django content management system
http://madewithwagtail.org
MIT License
84 stars 21 forks source link

Upgrade Django to fix possible vulnerability #135

Closed mojeto closed 5 years ago

mojeto commented 5 years ago

more info https://docs.djangoproject.com/en/1.11/releases/1.11.15/

I think Wagtail is safe, because it doesn't allow . character in page slugs. therefore path to a different domain (with dot) isn't going to be resolved and redirected.