OSV 1.4.0 · github-reviewed · 修改于 2026-06-30 07:03
发布时间
2026-05-26 21:30
GitHub 审查时间
2026-06-30 07:03
NVD 发布时间
2026-05-22 23:16
源文件
advisories/github-reviewed/2026/05/GHSA-jqvq-gv67-3567/GHSA-jqvq-gv67-3567.json
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog. This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. Thanks Winston Crooker for reporting.