PT-2026-85036 · Crmeb · Crmeb
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
CRMEB through 6.0.0 fails to validate message ownership in the edit message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns including is del, look, and uid to delete, mark read, or reassign victim notifications without authorization.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crmeb