IsItPatchedInstant security status for any software version
← All products

CVE-2014-0483

LOW severity · CVSS 3.5 · CWE-264
3.5CVSS LOW

Summary

The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI.

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impact
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)0%

AV:N/AC:M/Au:S/C:P/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: https://github.com/django/django/commit/2b31342cdf14fc20e07c43d258f1e7334ad664a6 ↗

Last checked: Wed, 10 Jun 2026 22:18:30 UTC