Description
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form pages they don-t have access to by crafting a form submission to delete submissions on a page they do have access to for submissions they don-t. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.
CVSS 6.5EPSS 0.174%Risque 0.66
Voir la source- Publication
- 2026-05-11 16:17:35
- Versions concernées
- <7.0.7, <7.3.2, <7.4
- Type
- Core software
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N