PT-2026-95217 · Pypi · Django-Page-Cms
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
django-page-cms versions prior to 2.0.14
Description
Insufficient validation of page permissions within admin helper views allows users with staff account privileges to read arbitrary page content and stored media paths. This flaw enables attackers with low-privilege staff credentials to enumerate content identifiers and gain unauthorized access to page listings, file paths, and unpublished drafts.
Recommendations
Update to version 2.0.14 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django-Page-Cms