Impact
The flaw in Wagtail’s Documents and Images chooser allows an authenticated admin to view the file names, URLs, and basic metadata of media items that they are not authorized to choose. This improper authorization (CWE‑280) does not give or system but exposes sensitive asset information. The vulnerability is only exploitable by users with Wagtail admin access; ordinary visitors cannot exploit it.
Affected Systems
Systems running Wagtail versions prior to 7.0.8, 7.3.3, or 7.4.2 are affected. The issue and images.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk severity. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an admin login; ordinary site visitors without admin access cannot exploit the flaw. The exploitation risk is thus low for external attackers but possible for authenticated Wagtail admins.
OpenCVE Enrichment