cve/2018/CVE-2018-6188.md
2024-05-26 14:27:05 +02:00

743 B

CVE-2018-6188

Description

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.

POC

Reference

No PoCs from references.

Github