CyberRota Analysis
AI-GeneratedA broken access control vulnerability in CSZ CMS 1.3.2 enables unauthenticated remote attackers to access all form submissions, including sensitive personally identifiable information, through the unprotected admin form-submission viewer. This flaw arises from the absence of an authentication check, allowing attackers to exploit the system without any credentials. Organizations using this CMS should prioritize remediation to protect user data and comply with privacy regulations.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission viewer. The viewer endpoint lacks an authentication check and the framework authentication helper fails open. An unauthenticated attacker can access all contact form submissions without credentials.