|
LinuxSecurity.com: A cross-site request forgery vulnerability was discovered in Django that, if exploited, could be used to perform unrequested deletion or modification of data. Updated versions of Django will now discard posts from users whose sessions have expired, so data will need to be re-entered in these cases.
Original Source: http://www.linuxsecurity.com/content/view/141236?rdf
Learn more about Mandriva: Subject: [Security Announce] [ MDVSA-2008:185 ] python-django |