CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns including is_del, look, and uid to delete, mark read, or reassign victim notifications without authorization.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 15:17
Updated : 2026-09-03 15:17
NVD link : CVE-2026-85177
Mitre link : CVE-2026-85177
CVE.ORG link : CVE-2026-85177
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
