Insufficient `content-type` validation in `post_comment`
minusf opened this issue · comments
minusf commented
Non-existing models are not handled.
From a recent security scan against our site:
Exception Type: LookupError at /c/post/
Exception Value: App 'wagtailcore' doesn't have a 'page' AND 1='1/*' model.
apps.get_model
returns LookupError
for non-existing models. This is not handled in the code.