Логотип exploitDog
bind:CVE-2026-30945
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-30945

Количество 2

Количество 2

nvd логотип

CVE-2026-30945

около 1 месяца назад

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user with editor privileges or above to revoke API tokens belonging to any other user, including admin and owner accounts. The handler accepts tokenID and userID directly from the request payload without verifying token ownership, caller identity, or role hierarchy. This enables targeted denial of service against critical integrations and automations. This vulnerability is fixed in 0.4.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-8rgj-vrfr-6hqr

около 1 месяца назад

StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Service

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-30945

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user with editor privileges or above to revoke API tokens belonging to any other user, including admin and owner accounts. The handler accepts tokenID and userID directly from the request payload without verifying token ownership, caller identity, or role hierarchy. This enables targeted denial of service against critical integrations and automations. This vulnerability is fixed in 0.4.0.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-8rgj-vrfr-6hqr

StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Service

CVSS3: 7.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу