Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 and 2.41.1 contain a patch.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensource-workshop
Opensource-workshop connect-cms |
|
| Vendors & Products |
Opensource-workshop
Opensource-workshop connect-cms |
Tue, 24 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 and 2.41.1 contain a patch. | |
| Title | Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information | |
| Weaknesses | CWE-285 CWE-639 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-23T21:40:59.009Z
Updated: 2026-03-23T21:40:59.009Z
Reserved: 2026-03-11T21:16:21.658Z
Link: CVE-2026-32300
No data.
Status : Received
Published: 2026-03-23T22:16:27.933
Modified: 2026-03-23T22:16:27.933
Link: CVE-2026-32300
No data.