According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated and possess the permissions for page creation to be able to exploit this vulnerability.
<a href="https://twitter.com/testanull">Nguyen Tien Giang</a> with <a href="https://twitter.com/starlabs_sg">STAR Labs</a>, Anonymous working with <a href="https://www.zerodayinitiative.com/">Trend Micro Zero Day Initiative</a>, <a href="https://twitter.com/_q5ca">Q5Ca</a> with <a href="https://khonggianmang.vn/">NCSC Vietnam</a>, Yuhao Weng & Zhiniang Peng & Feng Dong with <a href="https://www.sangfor.com/">Sangfor</a>