Описание
The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.
Ссылки
- Broken Link
- Not Applicable
- Not Applicable
- Third Party Advisory
- Patch
- Mailing ListThird Party Advisory
- Not Applicable
- Issue TrackingThird Party Advisory
- Broken Link
- Broken Link
- Broken Link
- Not Applicable
- Not Applicable
- Third Party Advisory
- Patch
- Mailing ListThird Party Advisory
- Not Applicable
- Issue TrackingThird Party Advisory
- Broken Link
- Broken Link
Уязвимые конфигурации
Одно из
EPSS
5.8 Medium
CVSS2
Дефекты
Связанные уязвимости
The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.
The administration application in Django 0.91, 0.95, and 0.96 stores u ...
Django cross-site request forgery (CSRF) vulnerability
EPSS
5.8 Medium
CVSS2