GHSA-8v5m-pr8j-m896HighCVSS 7.5

A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to...

Published
August 11, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission viewer. The viewer endpoint lacks an authentication check and the framework authentication helper fails open. An unauthenticated attacker can access all contact form submissions without credentials.

🔗 References (3)