Authorization Bypass Affecting django-newsletter package, versions [,0.7)
Snyk CVSS
Attack Complexity
Low
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-DJANGONEWSLETTER-42172
- published 2 Aug 2018
- disclosed 14 Jul 2014
- credit Unknown
How to fix?
Upgrade django-newsletter
to version 0.7 or higher.
Overview
django-newsletter is a Newsletter application for the Django web framework.
Affected versions of this package are vulnerable to Authorization Bypass. A user can change their email address without confirmation by receiving an update URL via email, accessing the form and changing the email address.