top of page
perceptive_background_267k.jpg

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload …

Published:

29 april 2026 om 22:00:00

Alert date:

30 april 2026 om 07:00:50

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

All versions of the django-mdeditor package are vulnerable to missing authentication for critical function in the image upload endpoint. The vulnerability allows attackers to upload malicious files without authentication and achieve arbitrary code execution. The endpoint lacks proper authentication protection and file name sanitization. This affects all versions of the package and has been assigned CVE-2025-13030. The vulnerability enables remote code execution through malicious file uploads.

Technical details

Mitigation steps:

Affected products:

django-mdeditor

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page