CRITICAL

CVE-2019-19844

CVSS v3

9.8

CRITICAL

EPSS Score

14.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)

Technical details

Published
12/18/2019

Frequently asked questions

What is CVE-2019-19844?

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)

Is CVE-2019-19844 actively exploited?

Active exploitation of CVE-2019-19844 has not been confirmed. The EPSS score is 14.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-19844?

CVE-2019-19844 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-19844 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.