THREAT OPS › Threat News › [GHSA] GHSA-jm5p-837g-rv8g (medium) — Wagtail: Improper restriction handling on Page translation API endpoint
[GHSA] GHSA-jm5p-837g-rv8g (medium) — Wagtail: Improper restriction handling on Page translation API endpoint
GHSA-jm5p-837g-rv8g Severity: medium CVE: None
Wagtail: Improper restriction handling on Page translation API endpoint
### Impact A CMS user with the "submit translations" permission, could use the Admin API's "copy for translation" endpoint to copy an existing page that they do not have edit access to, allowing them to view its contents.
### Patches Patched versions have been released as Wagta
Indicators of compromise
- https://docs.wagtail.org/en/stable/support.htmlurl
- security@wagtail.orgemail
Original source: https://github.com/advisories/GHSA-jm5p-837g-rv8g