—
PYSEC-2019-174
Details
Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportunities/create/, and /login/.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/django-crm
Introduced in:
0.2.1No fixed version published yet for django-crm (pip). Pin to a known-safe version or switch to an alternative.