---
title: "Note di rilascio di Django 1.11.21"
version: 5.2
locale: it
source: https://docs.djangoproject.com/it/5.2/releases/1.11.21/
canonical: https://djangodocs.dev/it/5.2/releases/1.11.21/
---
# Note di rilascio di Django 1.11.21

*3 Giugno 2019*

Django 1.11.21 risolve un problema di sicurezza in 1.11.20.

## CVE-2019-12308: AdminURLFieldWidget XSS

The clickable «Current URL» link generated by `AdminURLFieldWidget` displayed
the provided value without validating it as a safe URL. Thus, an unvalidated
value stored in the database, or a value provided as a URL query parameter
payload, could result in an clickable JavaScript link.

`AdminURLFieldWidget` now validates the provided value using
[`URLValidator`](/it/5.2/ref/validators/#django.core.validators.URLValidator) before displaying the clickable
link. You may customize the validator by passing a `validator_class` kwarg to
`AdminURLFieldWidget.__init__()`, e.g. when using
[`formfield_overrides`](/it/5.2/ref/contrib/admin/#django.contrib.admin.ModelAdmin.formfield_overrides).
