Impact
The vulnerability allows an attacker to bypass authentication checks within the geex‑arts django‑jet Dashboard Module. The flaw resides in an undocumented function in jet/dashboard/views.py and results in elevated privileges, enabling unauthorized users to access the admin dashboard. The defect falls under improper authorization weaknesses (CWE‑285) and). An attacker who exploits this flaw could read or modify administrative configuration, potentially compromising the entire application.
Affected Systems
The flaw affects installations of geex‑arts django‑jet at version 1.0.8 or earlier. It is relevant to all deployments that include the Dashboard Module in this or older releases. No additional product or version data is listed.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate risk. The EPSS score is below 1 %, suggesting that exploitation attempts are expected to be rare, and the vulnerability is not included in CISA’s KEV catalog. Exploitation can be carried out remotely by sending crafted requests to the dashboard endpoints. Because the issue is in has acknowledged the issue but has not yet released a patch, which increases the window of exposure.
OpenCVE Enrichment