An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is known or guessed.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| FormCMS(NuGet) | 0 | 0.5.5 | N/A |
CVSS Metrics