Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-64821— djangoSIGE 1.10 CSRF via GET-based Order Cancellation Views

CVSS 4.3 · Medium EPSS 0.15% · P5

Affected Version Matrix 2

VendorProductVersion RangeStatus
thiagopenadjangoSIGE≤ 1.10affected
≤ a6fe7e8e3a7d52ba0a25305df4e5e7e0cd5f5792affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-64821

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
djangoSIGE 1.10 CSRF via GET-based Order Cancellation Views
Source: CVE Program / CVE List V5
Vulnerability Description
djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated attackers to cancel sales or purchase orders on behalf of authenticated users by exploiting order-cancellation logic implemented inside HTTP GET method handlers in CancelarOrcamentoVendaView, CancelarPedidoVendaView, CancelarOrcamentoCompraView, and CancelarPedidoCompraView. Attackers can lure an authenticated victim with change_orcamentovenda or equivalent permissions to a page containing a cross-origin reference such as an img tag pointing to the cancellation endpoint, bypassing CSRF token validation entirely since Django's CsrfViewMiddleware only enforces CSRF checks on unsafe HTTP methods.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨站请求伪造(CSRF)
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
thiagopenadjangoSIGE 0 ~ 1.10 -

II. Public POCs for CVE-2026-64821

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-64821

登录查看更多情报信息。

Patches & Fixes for CVE-2026-64821 (1)

Vendor Advisories for CVE-2026-64821 (1)

Security Blog Posts for CVE-2026-64821 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-64821

No comments yet


Leave a comment