Beveiligingsadvies

CVE-2026-89265

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-11 15:25:19
Laatst bijgewerkt 2026-09-11 20:29:28
Toegewezen door VulnCheck
CVSS-score 5.3
Status PUBLISHED

Beschrijving

MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve restricted image-category records including metadata such as name, cover file uid, sort order and timestamps.