Webhook Authorization Vulnerability in Anymail by Anymail
CVE-2018-1000089
7.4HIGH
What is CVE-2018-1000089?
The Anymail Django library, versions 0.2 through 1.3, has a vulnerability in the WEBHOOK_AUTHORIZATION setting that may allow attackers with access to error logs to fabricate email tracking events. If Django error reports are exposed, an attacker could potentially discover the ANYMAIL_WEBHOOK setting and exploit it to submit forged or malicious tracking events to the application. This issue was addressed in version 1.4.
