ZeroHour

CVE-2016-2048

CVSS 3.0
5.5 medium
EPSS
2%p73
Published
()
Modified
Description

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

Vendors
djangoproject
Products
django
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.