OSV 1.4.0 · unreviewed · 修改于 2026-09-03 23:32
发布时间
2026-09-03 23:32
GitHub 审查时间
—
NVD 发布时间
2026-09-03 23:17
源文件
advisories/unreviewed/2026/09/GHSA-jr4r-3j8p-qx65/GHSA-jr4r-3j8p-qx65.json
CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests.
该公告没有提供结构化的受影响软件包信息。