{ "id": "CVE-2007-5828", "sourceIdentifier": "cve@mitre.org", "published": "2007-11-05T19:46:00.000", "lastModified": "2023-11-07T02:01:23.537", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module" }, { "lang": "es", "value": "** EN DISPUTA ** La vulnerabilidad de falsificaci\u00f3n de solicitudes entre sitios (CSRF) en el panel de administraci\u00f3n en Django 0.96 permite a los atacantes remotos cambiar las contrase\u00f1as de usuarios arbitrarios mediante una solicitud a admin / auth / user / 1 / password /. NOTA: Debian ha disputado este problema, ya que la documentaci\u00f3n del producto incluye una recomendaci\u00f3n para un m\u00f3dulo de protecci\u00f3n CSRF que se incluye con el producto. Sin embargo, CVE considera que esto es un problema porque la configuraci\u00f3n predeterminada no usa este m\u00f3dulo." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 6.8 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-352" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:django_project:django:0.96:*:*:*:*:*:*:*", "matchCriteriaId": "3F54F75F-B2BC-4A44-B93B-DB75856BEC45" } ] } ] } ], "references": [ { "url": "http://osvdb.org/45285", "source": "cve@mitre.org" }, { "url": "http://securityreason.com/securityalert/3338", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/archive/1/482983/100/0/threaded", "source": "cve@mitre.org" } ] }