Tuesday, December 4, 2012

django CMS security release issued

We just issued a security release for the django CMS to fix a vulnerability in the page_attribute template tag, which allowed admins with restricted permissions to elevate their permissions through XSS.

All django CMS users are encouraged to update their django CMS installations immediately.


- Jonas

--
You received this message because you are subscribed to the Google Groups "Django users" group.
To post to this group, send email to django-users@googlegroups.com.
To unsubscribe from this group, send email to django-users+unsubscribe@googlegroups.com.
For more options, visit this group at http://groups.google.com/group/django-users?hl=en.

No comments:

Post a Comment