PT-2026-3381 · Unknown · Sanluan Publiccms

·

CVE-2026-1112

·

Published

2026-01-18

·

Updated

2026-02-05

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sanluan PublicCMS versions up to 5.202506.d
Description A flaw exists in Sanluan PublicCMS that allows for improper authorization. This issue is related to the delete function within the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeAddressController.java of the Trade Address Deletion Endpoint component. Manipulation of the ids argument can trigger the issue, and the attack can be initiated remotely. The exploit has been publicly disclosed.
Recommendations Versions prior to 5.202506.d should be updated.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1112

Affected Products

Sanluan Publiccms