PT-2026-30715 · Brave Cms · Brave Cms
Para213
·
Published
2026-04-06
·
Updated
2026-04-06
·
CVE-2026-35183
CVSS v3.1
7.1
High
| AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Brave CMS versions prior to 2.0.6
Description
A flaw exists in the article image deletion feature of Brave CMS, specifically within the
deleteImage method in app/Http/Controllers/Dashboard/ArticleController.php. The affected endpoint does not verify ownership of the image file received from the URL, allowing an authenticated user with edit permissions to delete images associated with articles owned by other users. This is an Insecure Direct Object Reference (IDOR) issue.Recommendations
Update to version 2.0.6 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brave Cms