Description
The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1640-1 | New python-django packages fix cross site request forgery |
EUVD |
EUVD-2008-0003 | The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests. |
Github GHSA |
GHSA-r5cj-wv24-92p5 | Django cross-site request forgery (CSRF) vulnerability |
References
History
Thu, 16 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Djangoproject
Djangoproject django |
|
| CPEs | cpe:2.3:a:django_project:django:0.95:*:*:*:*:*:*:* cpe:2.3:a:django_project:django:0.96:*:*:*:*:*:*:* |
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* |
| Vendors & Products |
Django Project
Django Project django |
Djangoproject
Djangoproject django |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T09:53:00.640Z
Reserved: 2008-09-04T00:00:00.000Z
Link: CVE-2008-3909
No data.
Status : Analyzed
Published: 2008-09-04T17:41:00.000
Modified: 2026-04-16T21:11:39.260
Link: CVE-2008-3909
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA