CVE-2026-64821

Summary

djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated attackers to cancel sales or purchase orders on behalf of authenticated users by exploiting order-cancellation logic implemented inside HTTP GET method handlers in CancelarOrcamentoVendaView, CancelarPedidoVendaView, CancelarOrcamentoCompraView, and CancelarPedidoCompraView. Attackers can lure an authenticated victim with change_orcamentovenda or equivalent permissions to a page containing a cross-origin reference such as an img tag pointing to the cancellation endpoint, bypassing CSRF token validation entirely since Django's CsrfViewMiddleware only enforces CSRF checks on unsafe HTTP methods.

Affected Software

VendorProductVersion RangeStatus
thiagopenadjangoSIGE0 <= 1.10affected
thiagopenadjangoSIGE0 <= a6fe7e8e3a7d52ba0a25305df4e5e7e0cd5f5792affected

Weaknesses

  • CWE-352: Cross-Site Request Forgery (CSRF)

References