Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component Chapter Controller. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit is publicly available and might be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | light0011 cms Chapter Controller ChapterController.class.php _initialize authorization | |
| First Time appeared |
Light0011
Light0011 cms |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:light0011:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Light0011
Light0011 cms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-03T23:00:10.572Z
Reserved: 2026-09-03T17:53:41.934Z
Link: CVE-2026-85378
No data.
Status : Received
Published: 2026-09-03T23:17:20.987
Modified: 2026-09-03T23:17:20.987
Link: CVE-2026-85378
No data.
OpenCVE Enrichment
Updated: 2026-09-04T00:30:12Z
