Lucene search

K
prionPRIOn knowledge basePRION:CVE-2014-0483
HistoryAug 26, 2014 - 2:55 p.m.

Crlf injection

2014-08-2614:55:00
PRIOn knowledge base
www.prio-n.com
13

6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.8%

The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI.

6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.8%