Vulnerabilities
Vulnerable Software
Djangoproject:  >> Django  >> 1.9  Security Vulnerabilities
The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.
CVSS Score
3.1
EPSS Score
0.033
Published
2016-04-08
The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.
CVSS Score
7.4
EPSS Score
0.04
Published
2016-04-08
Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.
CVSS Score
5.5
EPSS Score
0.015
Published
2016-02-08


Contact Us

Shodan ® - All rights reserved