Executive brief
django-cms is a popular content management system plugin for Django web applications. This vulnerability allows attackers to exploit cross-site request forgery (CSRF) attacks to trick authenticated administrators into performing unauthorized actions, such as modifying pages or other site content without their knowledge or consent. An attacker could potentially manipulate a privileged user into making unintended changes to the website.
Technical details
The vulnerability is a cross-site request forgery (CSRF) vulnerability (CWE-352) in django-cms versions before 3.0.14 and 3.1.x before 3.1.1. Sensitive admin endpoints handling page management operations, such as `change_template`, `move_page`, and `copy_language`, lacked proper CSRF protection via POST-only decorators (e.g., `@require_POST`). An attacker can craft a malicious webpage that, when visited by an authenticated administrator, silently triggers unintended administrative actions. The fix involves adding CSRF protection decorators to affected endpoints. Patches are available in versions 3.0.14 and 3.1.1 and later.
Affected products
- Django CMS django-cms before 3.0.14, 3.1.x before 3.1.1
Timeline
- 2015-06-27: disclosed
- 2015-06-27: patched: Fixed in versions 3.0.14 and 3.1.1