Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Django Project 管理面板跨站请求伪造漏洞
Vulnerability Description
Django 0.96版本的管理面板中存在跨站请求伪造漏洞,远程攻击者借助对admin/auth/user/1/password/的一个请求更改任意用户的密码。注意:这个问题一直有被Debian认为有争议,因为产品文档包括一项CSRF的保护模块,该产品包括建议。
CVSS Information
N/A
Vulnerability Type
N/A