Gouguoa · Gouguoa · CVE-2026-84430
**Name of the Vulnerable Software and Affected Versions**
gouguoa versions 5.10.0 and earlier
gouguoa versions 6.0.1 and earlier
**Description**
A remote attack can be executed through the `update()` function within the `app/home/controller/Index.php` file of the `edit personal` endpoint. By manipulating the `position id` variable, an attacker can cause dynamically-determined object attributes.
**Recommendations**
Update gouguoa to version 6.0.3.