You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
An authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Learn more on MITRE.
Impact
An authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for.
Patches
This has been fixed in 5.73.16 and 6.7.2.