Description
The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2014-4289 Vulnerability (CVE-2014-4289)
WordPress Plugin Gantry 5 Framework Cross-Site Scripting (5.4.8)
WordPress Plugin Active Directory Integration/LDAP Integration Unspecified Vulnerability (3.6.95)
WebLogic CVE-2022-21616 Vulnerability (CVE-2022-21616)
WordPress Plugin Button Widget Smartsoft Cross-Site Request Forgery (1.0.1)