Executive brief
django-page-cms is a content management system plugin for Django that manages website pages and their permissions. A flaw in the admin helper views fails to properly validate user permissions, allowing any staff member—even those with low privileges—to read unpublished draft content, enumerate pages, and access stored media file paths that should be restricted.
Technical details
The vulnerability is a permission bypass in admin helper views within django-page-cms versions through 2.0.13. The root cause is insufficient authorization checks when handling page content requests. An attacker with any staff-level credentials can bypass permission controls to enumerate page identifiers, access unpublished drafts, retrieve page listings, and obtain file paths for stored media without proper authorization validation. The vulnerability requires network access and valid staff credentials, but does not require elevated admin privileges. No exploit mitigation or patch availability is mentioned in the advisory.
Affected products
- Batiste django-page-cms through 2.0.13
Timeline
- 2026-09-18: disclosed