GHSA-c94f-pm78-6rh7MediumCVSS 5.4

CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of...

Published
September 3, 2026
Last Modified
September 3, 2026

🔗 CVE IDs covered (1)

📋 Description

CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns including is_del, look, and uid to delete, mark read, or reassign victim notifications without authorization.

🔗 References (6)