VDB
Sign up
—

PYSEC-2019-174

Details

Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportunities/create/, and /login/.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django-crm
Introduced in: 0.2.1

No fixed version published yet for django-crm (pip). Pin to a known-safe version or switch to an alternative.

References