CVE-2007-5828
Dashboard / Vulnerabilities / CVE-2007-5828
CVE-2007-5828
Published: 5 Nov 2007Last Modified: 10 Apr 2026
Summary:
Details: Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module
References: http://osvdb.org/45285, http://securityreason.com/securityalert/3338, http://www.securityfocus.com/archive/1/482983/100/0/threaded
Affected packages
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
