CVE-2026-6611 | liangliangyy DjangoBlog up to 2.1.0.0 File Upload Endpoint djangoblog/settings.py SECRET_KEY hard-coded key
A vulnerability classified as problematic has been found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component File Upload Endpoint. Performing a manipulation of the argument SECRET_KEY results in use of hard-coded cryptographic key
.
This vulnerability is known as CVE-2026-6611. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More