No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be carried out remotely. Upgrading to version 1.3.0 is able to resolve this issue. The identifier of the patch is 799bb1210238f402c0c4948c8eedb6e61cd0c8d7. You should upgrade the affected component. | |
| Title | DjangoCRM django-crm Bulk Case Update bulk_views.py BulkUpdateCasesView authorization | |
| First Time appeared |
Djangocrm
Djangocrm django-crm |
|
| Weaknesses | CWE-862 CWE-863 |
|
| CPEs | cpe:2.3:a:djangocrm:django-crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Djangocrm
Djangocrm django-crm |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T17:57:14.310Z
Reserved: 2026-09-13T15:45:40.850Z
Link: CVE-2026-90806
Updated: 2026-09-14T17:56:49.217Z
Status : Deferred
Published: 2026-09-14T18:20:27.950
Modified: 2026-09-14T20:56:48.220
Link: CVE-2026-90806
No data.
OpenCVE Enrichment
No data.