PT-2026-66601 · Wolfcms · Wolf Cms
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wolf CMS versions prior to 0.8.3.2
Description
An authorization bypass exists in the
BackupRestoreController due to a PHP operator precedence flaw in the permission check expression. This allows authenticated users without administrative privileges to bypass access controls and perform restricted actions, including creating, downloading, and restoring backups.Recommendations
Update Wolf CMS to version 0.8.3.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wolf Cms