Description
A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in cleartext storage of sensitive information. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-07-19
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the file zinnia/views/mixins/entry_protection.py within the Fantomas42 django-blog-zinnia project and allows the cleartext storage of sensitive data. This flaw originates from improper handling of password protection, leading to the storage of credentials in an unencrypted form. The affected libraries may inadvertently expose passwords or other protected data if the file is accessed locally, potentially resulting in credential compromise and unauthorized access to protected content.

Affected Systems

Fantomas42’s django-blog-zinnia releases up to 0.20 are affected. The flaw is tied to the Protected Entry Password Handler component, and any deployment of these versions that utilizes local entry protection exposes the risk of storing passwords in a readable form.

Risk and Exploitability

The CVSS score of 4.8 places the issue in the moderate severity range, but the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability requires local access, meaning that an attacker must have at least local read or execution privileges to trigger the flaw. While the weakness has not entered the CISA KEV catalog, the cleartext storage of sensitive information aligns with CWE-312 and poses a significant confidentiality threat if locally accessed credentials are leaked.

Generated by OpenCVE AI on July 30, 2026 at 22:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest stable release of django-blog-zinnia that contains a fix for the entry protection flaw, or apply an available patch if the vendor announces one.
  • If upgrading is not possible, disable or remove the local entry protection feature that stores passwords, ensuring that any protected content is either removed or protected through an alternative secure mechanism.
  • Restrict local access to the application server using firewall rules, sudo permissions, or container isolation so that only trusted administrators can interact with the protected entry files.

Generated by OpenCVE AI on July 30, 2026 at 22:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 19 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in cleartext storage of sensitive information. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.
Title Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storage
First Time appeared Fantomas42
Fantomas42 django-blog-zinnia
Weaknesses CWE-310
CWE-312
CPEs cpe:2.3:a:fantomas42:django-blog-zinnia:*:*:*:*:*:*:*:*
Vendors & Products Fantomas42
Fantomas42 django-blog-zinnia
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Fantomas42 Django-blog-zinnia
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-20T13:22:26.672Z

Reserved: 2026-07-18T08:52:44.014Z

Link: CVE-2026-16213

cve-icon Vulnrichment

Updated: 2026-07-20T13:22:11.102Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T22:45:04Z

Weaknesses