views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..%2f..%2f path traversal when serving protected media.
"https://github.com/pypa/advisory-database/blob/main/vulns/coderedcms/PYSEC-2023-210.yaml"