3.5
CVSSv2

CVE-2014-0483

Published: 26/08/2014 Updated: 30/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

The administrative interface (contrib.admin) in Django prior to 1.4.14, 1.5.x prior to 1.5.9, 1.6.x prior to 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 12.3

opensuse opensuse 13.1

djangoproject django 1.5.3

djangoproject django 1.5.4

djangoproject django 1.5

djangoproject django 1.5.5

djangoproject django 1.5.6

djangoproject django 1.5.7

djangoproject django 1.5.8

djangoproject django 1.5.1

djangoproject django 1.5.2

djangoproject django 1.6

djangoproject django 1.6.1

djangoproject django 1.6.2

djangoproject django 1.6.3

djangoproject django 1.6.4

djangoproject django 1.6.5

djangoproject django 1.4

djangoproject django 1.4.4

djangoproject django 1.4.5

djangoproject django 1.4.1

djangoproject django 1.4.10

djangoproject django 1.4.6

djangoproject django 1.4.7

djangoproject django 1.4.11

djangoproject django 1.4.12

djangoproject django 1.4.8

djangoproject django 1.4.9

djangoproject django

djangoproject django 1.4.2

djangoproject django 1.7

Vendor Advisories

Debian Bug report logs - #775375 python-django: CVE-2015-0219 CVE-2015-0220 CVE-2015-0221 CVE-2015-0222 Package: src:python-django; Maintainer for src:python-django is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 14 Jan 2015 ...
Several security issues were fixed in Django ...
Several vulnerabilities were discovered in Django, a high-level Python web development framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2014-0480 Florian Apolloner discovered that in certain situations, URL reversing could generate scheme-relative URLs which could unexpectedly redirect ...
The administrative interface (contribadmin) in Django before 1414, 15x before 159, 16x before 166, and 17 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change for ...