Safety vulnerability ID: 36142
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Kotti 1.3.2 and 2.0.0b2 include a fix for CVE-2018-9856: Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a permission change via a /admin-document/@@share request.
https://github.com/advisories/GHSA-3hq4-f2v6-q338
Latest version: 2.0.9
A high-level, Pythonic web application framework based on Pyramid and SQLAlchemy. It includes an extensible Content Management System called the Kotti CMS.
------------------
**This release fixes a CSRF (Cross Site Request Forgery) security vulnerablity which was reported in 551. You should upgrade your installations ASAP.**
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application