Description
The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.
Remediation
References
Related Vulnerabilities
WordPress Plugin Eshop Magic Arbitrary File Disclosure (0.1)
WordPress Plugin Testimonial Rotator Cross-Site Scripting (3.0.3)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.25)
WordPress Plugin Responsive Menu-Create Mobile-Friendly Menu Multiple Vulnerabilities (3.1.3)
WordPress Plugin BuddyPress Multiple Cross-Site Request Forgery Vulnerabilities (2.8.1)