No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 25 Sep 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/controller/admin/sys/SysUserAdminController.java of the component exportExcel/exportData. This manipulation of the argument userId/deptId causes authorization bypass. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Sanluan PublicCMS exportExcel/exportData SysUserAdminController.java CmsContentAdminController authorization | |
| First Time appeared |
Publiccms
Publiccms publiccms |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:publiccms:publiccms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Publiccms
Publiccms publiccms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-25T05:45:10.045Z
Reserved: 2026-09-25T00:36:49.843Z
Link: CVE-2026-97721
No data.
Status : Received
Published: 2026-09-25T06:16:52.347
Modified: 2026-09-25T06:16:52.347
Link: CVE-2026-97721
No data.
OpenCVE Enrichment
No data.