PT-2008-5242 · Django · Django
Steve Milner
·
Published
2008-09-04
·
Updated
2022-05-02
·
CVE-2008-3909
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Django versions 0.91 through 0.96
Description
The administration application in Django stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, allowing remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.
Recommendations
For Django versions 0.91 through 0.96, consider disabling the administration application until a patch is available to prevent cross-site request forgery (CSRF) attacks. Restrict access to the administration interface to minimize the risk of exploitation. Avoid using the administration application for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django