PT-2026-3381 · Unknown · Sanluan Publiccms
Ana10Gy
·
Published
2026-01-18
·
Updated
2026-02-05
·
CVE-2026-1112
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sanluan PublicCMS versions up to 5.202506.d
Description
A flaw exists in Sanluan PublicCMS that allows for improper authorization. This issue is related to the
delete function within the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeAddressController.java of the Trade Address Deletion Endpoint component. Manipulation of the ids argument can trigger the issue, and the attack can be initiated remotely. The exploit has been publicly disclosed.Recommendations
Versions prior to 5.202506.d should be updated.
Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sanluan Publiccms