A low-privileged user can modify and delete admin articles by changing the value of the article[id] parameter prior to 9.2.9.
{
"nvd_published_at": "2022-05-23T12:16:00Z",
"cwe_ids": [
"CWE-284",
"CWE-639",
"CWE-732"
],
"severity": "MODERATE",
"github_reviewed_at": "2022-06-02T20:38:50Z",
"github_reviewed": true
}