PT-2026-93862 · Unknown · Continew Admin
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ContiNew Admin versions prior to 4.1.1
Description
An authorization bypass exists in the personal message delete endpoint. Authenticated users can delete messages and announcements belonging to other users by providing arbitrary message identifiers in the
IdsReq parameter. This allows for the removal of any message row and the purging of read receipts for all recipients because the system fails to validate ownership of the messages.Recommendations
Update to a version later than 4.1.0.
Restrict access to the personal message delete endpoint to minimize the risk of unauthorized message deletion.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Continew Admin