Impact
This vulnerability stems from a failure to validate page permissions in admin helper views, allowing staff users to read arbitrary page content, including unpublished drafts, page listings, and stored media paths. The missing authorization check (CWE-862) compromises confidentiality by exposing sensitive page data to any user with staff credentials, potentially leading to internal data leakage or aiding further attacks. No code execution or escalation of privileges is described, so the primary risk is data disclosure rather than system compromise.
Affected Systems
The flaw is present in django-page-cms versions up to 2.0.13, as maintained by batiste. Administrators using any of these releases that have staff accounts configured for the admin interface are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity, but the EPSS score of less than 1% suggests a very low probability of exploitation under current conditions. The issue is not listed in the CISA KEV catalog, further reducing the risk of widespread exploitation. Attackers require valid staff credentials, implying the vector is a compromised or misconfigured account rather than a remote network attack. If staff accounts are improperly granted, the vulnerability can be exercised locally within the application context, allowing enumeration of page IDs and media paths.
OpenCVE Enrichment