CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.
Severity
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
Atk. Vector
NETWORK
Atk. Complexity
LOW
Priv. Required
HIGH
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
djangoprojectdjango
1.9
djangoprojectdjango
1.9.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-django
bullseye (security)
2:2.2.28-1~deb11u2
fixed
bullseye
2:2.2.28-1~deb11u2
fixed
jessie
not-affected
wheezy
not-affected
squeeze
not-affected
bookworm
3:3.2.19-1+deb12u1
fixed
bookworm (security)
3:3.2.19-1+deb12u1
fixed
sid
3:4.2.16-1
fixed
trixie
3:4.2.16-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-django
wily
not-affected
vivid
not-affected
trusty
not-affected
precise
not-affected