#VU82274 Direct Request ('Forced Browsing') in wagtail - CVE-2023-45809

 

#VU82274 Direct Request ('Forced Browsing') in wagtail - CVE-2023-45809

Published: October 20, 2023


Vulnerability identifier: #VU82274
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-45809
CWE-ID: CWE-425
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
wagtail
Software vendor:
Torchbox

Description

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to improper access control. A remote administrator can make a direct URL request to the admin view that handles bulk actions on user accounts and gain access to sensitive information on the system.


Remediation

Install updates from vendor's website.

External links