PT-2008-5242 · Django · Django

Steve Milner

·

Published

2008-09-04

·

Updated

2022-05-02

·

CVE-2008-3909

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Django versions 0.91 through 0.96
Description The administration application in Django stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, allowing remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.
Recommendations For Django versions 0.91 through 0.96, consider disabling the administration application until a patch is available to prevent cross-site request forgery (CSRF) attacks. Restrict access to the administration interface to minimize the risk of exploitation. Avoid using the administration application for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3909
DSA-1640-1
GHSA-R5CJ-WV24-92P5
PYSEC-2008-2

Affected Products

Django