Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/CSZ-CMS/CSZ-CMS-V1.3 |
|
Tue, 11 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission viewer. The viewer endpoint lacks an authentication check and the framework authentication helper fails open. An unauthenticated attacker can access all contact form submissions without credentials. | |
| Title | CSZ CMS CSZ CMS - Broken Access Control | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T12:13:39.879Z
Reserved: 2026-08-10T10:33:03.257Z
Link: CVE-2026-72601
Updated: 2026-08-11T12:13:36.558Z
Status : Received
Published: 2026-08-11T12:17:43.143
Modified: 2026-08-11T13:19:04.100
Link: CVE-2026-72601
No data.
OpenCVE Enrichment
Updated: 2026-08-11T17:00:11Z