Impact
django-page-cms versions up to 2.0.13 mistakenly exclude five admin mutation views from CSRF protection. This omission allows an attacker to forge requests that modify page content without needing a CSRF token. The attacker can trick any signed‑in editor into visiting a malicious page, causing the editor to unknowingly submit a request that stores unescaped content. That stored content then renders for all site visitors, delivering stored cross‑site scripting attacks that can execute arbitrary JavaScript on the client side.
Affected Systems
The vulnerability affects the Django (Python) CMS package "django-page-cms" from publisher batiste, impacting all releases through version 2.0.13 inclusive. Administrators using any of these versions exposed to the admin mutation views are at risk.
Risk and Exploitability
The CVSS score of 8.4 identifies this flaw as high severity. The EPSS score of < 1% indicates that, at the time of analysis, the likelihood of exploitation is low, and it is not currently listed in the CISA KEV catalog. However, the exploit requires the attacker to lure a legitimate editor to a malicious page, forcing a forged request to alter page content. Once successful, all site visitors are exposed to injected scripts, compromising confidentiality and integrity of the site’s content. Attack vectors rely on user interaction, HTTP request forging, and the presence of an authenticated session.
OpenCVE Enrichment