Improper access control in wagtail - CVE-2022-21683
Published: January 18, 2022 / Updated: May 5, 2026
wagtail
Torchbox
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in comment reply notifications when sending notifications for new replies in comment threads. A remote user can leave a comment or reply somewhere on the site to disclose sensitive information.
User interaction is required for notification delivery.