Description
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.
Remediation
References
Related Vulnerabilities
Oracle JRE Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2026-22007)
WordPress Plugin Translate WordPress with GTranslate Cross-Site Scripting (2.8.64)
Apache HTTP Server Other Vulnerability (CVE-2001-1449)
MyBB Other Vulnerability (CVE-2010-4628)
WordPress Plugin FireDrum Email Marketing PHP Object Injection (1.47)