PT-2026-30389 · Unknown · Dromara Lamp-Cloud
Aibot88
·
Published
2026-04-05
·
Updated
2026-04-05
·
CVE-2026-5529
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dromara lamp-cloud versions up to 5.8.1
Description
A flaw exists in the
pageUser function within the /defUser/pageUser file of the DefUserController component, leading to improper authorization. This issue is remotely exploitable. The exploit is publicly available.Recommendations
For versions up to 5.8.1, address the improper authorization in the
pageUser function of the /defUser/pageUser file within the DefUserController component.Exploit
Fix
Incorrect Privilege Assignment
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dromara Lamp-Cloud