Impact
A vulnerability was discovered in DjangoCRM django‑crm, affecting the BulkUpdateCasesView in bulk_views.py. The flaw allows an attacker to invoke a bulk case update operation without proper authorization, enabling unauthorized modification of case data. This issue is a manifestation of Missing Authorization and Authorization Bypass weaknesses, permitting changes to multiple cases at once.
Affected Systems
The flaw exists in DjangoCRM django‑crm versions 1.2 and earlier. Upgrading to version 1.3.0, which includes the patch identified by commit 799bb1210238f402c0c4948c8eedb6e61cd0c8d7, removes the vulnerability.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating moderate severity. No EPSS data is available and it is not listed in the CISA KEV catalogue, suggesting it is not actively exploited in the wild. The description states that the attack is possible to be carried out remotely; the likely attack vector is via the bulk update endpoint, which an unauthenticated or improperly authorized user could reach if upstream access controls are insufficient.
OpenCVE Enrichment