CVE-2022-21683 is a medium-severity information disclosure vulnerability affecting Wagtail, a Django-based content management system. The flaw allows authenticated users to receive notifications for new comment replies on pages they lack editing access to, provided they have commented anywhere on the site. This could lead to unauthorized access to sensitive information. The vulnerability has a CVSS score of 4.3 (MEDIUM) with a low attack complexity and no user interaction required. While the direct impact is limited to information disclosure (C:L), it could expose internal discussions or content prematurely. There is no evidence of active exploitation, nor are there public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.13, < 2.15.2CPE matchmatch criteria | cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.