Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns including is_del, look, and uid to delete, mark read, or reassign victim notifications without authorization. | |
| Title | CRMEB through 6.0.0 Unauthorized Message Modification via edit_message | |
| First Time appeared |
Crmeb
Crmeb crmeb |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:crmeb:crmeb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Crmeb
Crmeb crmeb |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T14:24:50.290Z
Reserved: 2026-09-03T11:08:17.526Z
Link: CVE-2026-85177
Updated: 2026-09-03T14:24:45.972Z
Status : Received
Published: 2026-09-03T15:17:38.767
Modified: 2026-09-03T15:17:38.767
Link: CVE-2026-85177
No data.
OpenCVE Enrichment
Updated: 2026-09-03T16:00:07Z
-
CWE-639
Authorization Bypass Through User-Controlled Key