CVE-2013-0305 describes a permission bypass vulnerability in the administrative interface of Django versions 1.3.x, 1.4.x, and 1.5. Specifically, authenticated administrators could access sensitive object history information without proper authorization. This vulnerability has a CVSS score of 4.0, indicating a low severity, as it requires authentication and only allows for information disclosure (confidentiality impact). There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:1.3:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:1.3:alpha1:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:1.3:beta1:*:*:*:*:*:* | ||
1.3.1CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:1.3.1:*:*:*:*:*:*:* | ||
1.3.2CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:1.3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.