django-newsletter@0.2.5 vulnerabilities

Django app for managing multiple mass-mailing lists with both plaintext as well as HTML templates (and pluggable WYSIWYG editors for messages), images and a smart queueing system all right from the admin interface.

Direct Vulnerabilities

Known vulnerabilities in the django-newsletter package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Authorization Bypass

django-newsletter is a Newsletter application for the Django web framework.

Affected versions of this package are vulnerable to Authorization Bypass. A user can change their email address without confirmation by receiving an update URL via email, accessing the form and changing the email address.

How to fix Authorization Bypass?

Upgrade django-newsletter to version 0.7 or higher.

[,0.7)