PT-2026-93858 · Changeweder · Crm

·

CVE-2026-92402

·

Published

2026-09-16

·

Updated

2026-09-22

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ChangeWeDer crm (affected versions not specified)
Description A security flaw allows remote attackers to bypass authorization. The issue resides in the index() function within the UserController.java file of the top.upstudy.crm.controller.UserController component.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the index() function in the UserController.java file to minimize the risk of exploitation.

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92402

Affected Products

Crm