THREAT OPS › Threat News › [GHSA] GHSA-4xfr-4p46-gc6p (medium) — django CMS: Clipboard copy IDOR discloses unauthorized plugin content
[GHSA] GHSA-4xfr-4p46-gc6p (medium) — django CMS: Clipboard copy IDOR discloses unauthorized plugin content
GHSA-4xfr-4p46-gc6p Severity: medium CVE: CVE-2026-54622
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
### Summary The clipboard copy paths of the `copy_plugins` admin endpoint validate only the target (the user's own clipboard) and skip source-side authorization. A staff user can copy plugins out of a placeholder they have no permission on into their clipboard, the
Indicators of compromise
- CVE-2026-54622cve
Original source: https://github.com/advisories/GHSA-4xfr-4p46-gc6p