Intel

AIKIDO-2024-10111

wagtail is vulnerable to Improper Access Control

Improper Access ControlCVE-2024-35228 Published May 31, 2024

10

Low Risk

This Affects:

pythonwagtail
0.1 - 6.0.4
Fixed in 6.0.5
6.1.0 - 6.1.1
Fixed in 6.1.2
Are you affected? Scan for Free

TL;DR

Affected versions of wagtail are vulnerable to an improper access control vulnerability. A user with limited access to Wagtail administration panel can update and access settings of models where they do not have access to.

Who does this affect?

You are affected if you use a vulnerable version of wagtail.

Background info

wagtail is vulnerable to Improper Access Control in versions 0.1 - 6.0.4 and 6.1.0 - 6.1.1.

How to fix this

Upgrade wagtail to one of the patch versions.