Safety vulnerability ID: 33128
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console) in the Google App Engine Python SDK before 1.5.4 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary Python code via the code parameter.
Latest version: 1.5.1
Google AppEngine (unofficial easy-installable version of AppEngine SDK)
Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console) in the Google App Engine Python SDK before 1.5.4 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary Python code via the code parameter.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application