SB20261007218 - Multiple vulnerabilities in Django CRM



SB20261007218 - Multiple vulnerabilities in Django CRM

Published: October 7, 2026

Security Bulletin ID SB20261007218
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Partial DoS

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to consume server and outbound-email resources and delay users' sign-in.

The vulnerability exists due to allocation of resources without per-client or site-wide throttling in MagicLinkRequestView when handling passwordless sign-in requests. A remote attacker can submit requests using different recipient addresses or exhaust a specific recipient's hourly allowance to consume server and outbound-email resources and delay users' sign-in.

Each request creates a sign-in token and queues an email, and recipients need not be registered users. Targeted sign-in delays can last up to an hour, but a generated link still reaches the recipient's inbox. Exploitation does not provide authentication bypass, data disclosure, or access to another user's account.


2) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to consume server and outbound-email resources and delay users' sign-in.

The vulnerability exists due to allocation of resources without per-client or overall throttling in PortalLoginRequestView when handling portal sign-in requests. A remote attacker can submit requests using different recipient addresses or exhaust a specific recipient's hourly allowance to consume server and outbound-email resources and delay users' sign-in.

Email is sent only to existing contacts of the specified organization; requests for other addresses incur a database lookup instead. Targeted sign-in delays can last up to an hour, but a generated link still reaches the recipient's inbox. Exploitation does not provide authentication bypass, data disclosure, or access to another user's account.


3) Improper control of interaction frequency (CVE-ID: N/A)

CWE-ID: CWE-799 - Improper Control of Interaction Frequency

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service for other public web form visitors.

The vulnerability exists due to improper accounting of requests rejected by per-client rate limits in public web form endpoints when enforcing shared per-form limits. A remote attacker can repeatedly submit requests exceeding the per-client limit to exhaust the shared allowance and cause a denial of service for other public web form visitors.


4) Improper control of interaction frequency (CVE-ID: N/A)

CWE-ID: CWE-799 - Improper Control of Interaction Frequency

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service for other help center visitors.

The vulnerability exists due to improper accounting of requests rejected by per-client rate limits in help center endpoints when enforcing shared per-help-center limits. A remote attacker can repeatedly submit requests exceeding the per-client limit to exhaust the shared allowance and cause a denial of service for other help center visitors.


5) Improper control of interaction frequency (CVE-ID: N/A)

CWE-ID: CWE-799 - Improper Control of Interaction Frequency

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service for other calendar feed visitors.

The vulnerability exists due to improper accounting of requests rejected by per-client rate limits in calendar feed endpoints when enforcing shared per-feed limits. A remote attacker can repeatedly submit requests exceeding the per-client limit to exhaust the shared allowance and cause a denial of service for other calendar feed visitors.


Remediation

Install update from vendor's website.