Junglewise Threat Intelligence

CVE-2015-5081: PYSEC-2017-11 - Cross-site request forgery (CSRF) vulnerability in django CMS before 3.0.14, 3.1.x before 3.1.1 allows remote attackers to manipulate privil

CVE-2015-5081 · Severity: low · CVSS 3 · Published 2017-08-18

Technologies: Django CMS Django-Cms. Vendors: PyPI.

Executive brief

django-cms is a popular content management system plugin for Django web applications. This vulnerability allows attackers to exploit cross-site request forgery (CSRF) attacks to trick authenticated administrators into performing unauthorized actions, such as modifying pages or other site content without their knowledge or consent. An attacker could potentially manipulate a privileged user into making unintended changes to the website.

Technical details

The vulnerability is a cross-site request forgery (CSRF) vulnerability (CWE-352) in django-cms versions before 3.0.14 and 3.1.x before 3.1.1. Sensitive admin endpoints handling page management operations, such as `change_template`, `move_page`, and `copy_language`, lacked proper CSRF protection via POST-only decorators (e.g., `@require_POST`). An attacker can craft a malicious webpage that, when visited by an authenticated administrator, silently triggers unintended administrative actions. The fix involves adding CSRF protection decorators to affected endpoints. Patches are available in versions 3.0.14 and 3.1.1 and later.

Affected products

  • Django CMS django-cms before 3.0.14, 3.1.x before 3.1.1

Timeline

  • 2015-06-27: disclosed
  • 2015-06-27: patched: Fixed in versions 3.0.14 and 3.1.1

References

Related threats