PT-2026-96308 · Unknown · Lamp-Cloud

·

CVE-2026-94534

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions lamp-cloud versions prior to 5.10.1
Description The software fails to validate user identity in the 'PUT /anyone/baseInfo' and 'PUT /anyone/avatar' endpoints. This allows authenticated attackers to modify arbitrary user profiles by supplying target user IDs in the request bodies. Affected profile fields include nickname, ID card, sex, nation, education, work description, and avatar attachments.
Recommendations Update lamp-cloud to a version newer than 5.10.0. Restrict access to the 'PUT /anyone/baseInfo' and 'PUT /anyone/avatar' endpoints to minimize the risk of exploitation.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94534

Affected Products

Lamp-Cloud