GHSA-pg2f-r7pc-6fxx
Dashboard / Vulnerabilities / GHSA-pg2f-r7pc-6fxx
GHSA-pg2f-r7pc-6fxx
Summary: Cross-Site Request Forgery in MicroPyramid Django CRM
Details: Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportunities/create/, and /login/.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-11457, https://github.com/MicroPyramid/Django-CRM, https://github.com/advisories/GHSA-pg2f-r7pc-6fxx, https://github.com/pypa/advisory-database/tree/main/vulns/django-crm/PYSEC-2019-174.yaml, https://www.netsparker.com/blog/web-security, http://packetstormsecurity.com/files/154219/Django-CRM-0.2.1-Cross-Site-Request-Forgery.html, http://seclists.org/fulldisclosure/2019/Aug/30
Affected packages
Package
Name: django-crm
Purl: pkg:pypi/django-crm
Affected ranges
Type: ECOSYSTEM
Events:
