The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update action and overwrite that record without a valid edit link or any ownership check.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 09:17
Updated : 2026-08-27 20:18
NVD link : CVE-2026-77140
Mitre link : CVE-2026-77140
CVE.ORG link : CVE-2026-77140
JSON object : View
Products Affected
No product.
