Executive brief
newpanjing simpleui is a popular theme and interface enhancement for the Django administration panel. A security flaw in its AJAX handling component allows unauthorized users to bypass standard login requirements and execute administrative actions. This could lead to unauthorized data modification or access to sensitive management functions without a valid account.
Technical details
A vulnerability exists in simpleui/admin.py within the AjaxAdmin component of newpanjing simpleui. The issue stems from the `get_urls` method registering custom AJAX and layer ModelAdmin URLs without wrapping them in Django's `admin_site.admin_view()` decorator. Consequently, the `get_action` function and subsequent execution logic do not verify if the requester is authenticated or possesses the necessary permissions for the requested model action. A remote, unauthenticated attacker can exploit this by sending crafted POST requests to the AJAX endpoint to execute arbitrary administrative actions on querysets. As of the advisory date, the project has been notified but a formal patch has not been confirmed.
Affected products
- newpanjing simpleui 2026.01.13
Timeline
- 2026-06-13: disclosed: Issue reported via GitHub issue #537
- 2026-07-19: advisory: CVE published by NVD/VulDB