PT-2026-84572 · Gouguoa · Gouguoa

·

CVE-2026-84430

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gouguoa versions 5.10.0 and earlier gouguoa versions 6.0.1 and earlier
Description A remote attack can be executed through the update() function within the app/home/controller/Index.php file of the edit personal endpoint. By manipulating the position id variable, an attacker can cause dynamically-determined object attributes.
Recommendations Update gouguoa to version 6.0.3.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84430

Affected Products

Gouguoa