Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-67207

Опубликовано: 30 июл. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the access control expression to create, download, and restore backups without administrative privileges.

EPSS

Процентиль: 22%
0.003
Низкий

8.8 High

CVSS3

Дефекты

CWE-697

Связанные уязвимости

CVSS3: 8.8
github
7 дней назад

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the access control expression to create, download, and restore backups without administrative privileges.

EPSS

Процентиль: 22%
0.003
Низкий

8.8 High

CVSS3

Дефекты

CWE-697