An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is known or guessed.
| Software | From | Fixed in |
|---|---|---|
FormCMS
|
- | 0.5.5 |
| formcms / formcms | 0.5.4 | 0.5.4.x |