PT-2026-29433 · Gougucms · Gougucms

Thinhnee

+1

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-5248

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gougucms version 4.08.18
Description A flaw exists in gougucms version 4.08.18 within the User Registration Handler component. Specifically, the reg submit function in the file gougucms-masterapphomecontrollerLogin.php is susceptible to manipulation of the level argument, resulting in dynamically-determined object attributes. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2026-5248

Affected Products

Gougucms