Impact
The vulnerability resides in the OAuth Handler component of geex‑arts django‑jet, enabling an attacker to send crafted requests that may cause the application to perform actions on behalf of an authenticated user. The CVE states that such a manipulation can lead to cross‑site request forgery, suggesting remote exploitation. It is inferred that the user may be unaware of these unintended actions. The weakness is identified as CWE‑352.
Affected Systems
Geex‑arts django‑jet versions up to and including 1.0.8 are affected. The advisory notes that the maintainers have received the issue report but have not yet released a fix, meaning any installation still using these releases remains vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the exploit has been made publicly available, it is inferred that attackers could leverage existing exploitation code. The attacker would likely need the target application to be reachable from the internet, identify a valid OAuth flow, and subvert it via a forged request. The attack vector is remote, and the impact is limited to coerced user sessions or roles.
OpenCVE Enrichment