CyberRota Analysis
AI-GeneratedA vulnerability in the BulkUpdateCasesView function of DjangoCRM's Bulk Case Update component allows for missing authorization, potentially enabling remote attackers to manipulate case updates. Organizations using DjangoCRM versions up to 1.2 should prioritize upgrading to version 1.3.0 to mitigate this risk and ensure proper access controls are enforced.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be carried out remotely. Upgrading to version 1.3.0 is able to resolve this issue. The identifier of the patch is 799bb1210238f402c0c4948c8eedb6e61cd0c8d7. You should upgrade the affected component.