CVE-2026-84430CWE-913CWE-915

CVE-2026-84430

Medium · published September 2, 2026

CVSS v3.1
6.3
EPSS
0%
Percentile
15.9
In the wild
Unconfirmed
What it is

A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 6.0.3 is able to resolve this issue. Upgrading the affected component is advised.

The record
Technical detail
CVSS v3.1
6.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
EPSS
0.00247 · 15.9th percentile
Weaknesses
CWE-913 · Improper Control of Dynamically-Managed Code Resources; CWE-915 · Improperly Controlled Modification of Dynamically-Determined Object Attributes
Published
2026-09-02T05:17Z
References (6)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 02 SEP 00:45Z
    gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
    cvelistv5