GHSA-v2qc-hf9w-393gHighCVSS 6.5

django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views,...

Published
September 18, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumerate content identifiers and access unpublished drafts, page listings, and file paths without proper authorization checks.

🔗 References (8)