Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Saidakbarxon Maqsudxonov

#31275of 56,330
8.8Total CVSS
Vulnerabilities · 1
PT-2026-52858
8.8
2026-06-26
Unknown · Pagekit Cms · CVE-2026-57518
**Name of the Vulnerable Software and Affected Versions** Pagekit CMS version 1.0.18 **Description** An issue exists where authenticated users possessing the 'user: manage users' permission can escalate their privileges. This occurs due to missing authorization checks within the `saveAction()` function of the `UserApiController`. An attacker can exploit this to assign themselves a custom role with the 'system: manage packages' permission, subsequently allowing them to upload and install a malicious PHP package via the admin package installer to achieve remote code execution. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.