Django Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2013-0305 - Vulnerability Database

Django Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2013-0305

Medium
Reference: CVE-2013-0305
Title: Django Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

The administrative interface for Django 1.3.x before 1.3.6 1.4.x before 1.4.4 and 1.5 before release candidate 2 does not check permissions for the history view which allows remote authenticated administrators to obtain sensitive object history information.