Home

Description

A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the file publiccms-parent/publiccms-trade/src/main/java/com/publiccms/logic/service/trade/TradePaymentService.java of the component Trade Payment Handler. The manipulation of the argument paymentId leads to improper authorization. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 7329437e1288540336b1c66c114ed3363adcba02. It is recommended to apply a patch to fix this issue.

PUBLISHED Reserved 2026-02-05 | Published 2026-02-06 | Updated 2026-02-06 | Assigner VulDB




LOW: 2.3CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
MEDIUM: 4.2CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C
MEDIUM: 4.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C
3.6AV:N/AC:H/Au:S/C:N/I:P/A:P/E:POC/RL:OF/RC:C

Problem types

Improper Authorization

Incorrect Privilege Assignment

Product status

4.0.202506.a
affected

4.0.202506.b
affected

4.0.202506.c
affected

4.0.202506.d
affected

5.202506.a
affected

5.202506.b
affected

5.202506.c
affected

5.202506.d
affected

6.202506.a
affected

6.202506.b
affected

6.202506.c
affected

6.202506.d
affected

Timeline

2026-02-05:Advisory disclosed
2026-02-05:VulDB entry created
2026-02-05:VulDB entry last update

Credits

AliceS614 (VulDB User) reporter

References

vuldb.com/?id.344592 (VDB-344592 | Sanluan PublicCMS Trade Payment TradePaymentService.java paid improper authorization) vdb-entry technical-description

vuldb.com/?ctiid.344592 (VDB-344592 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/?submit.743487 (Submit #743487 | PublicCMS 5 Improper Access Controls) third-party-advisory

github.com/sanluan/PublicCMS/issues/108 issue-tracking

github.com/sanluan/PublicCMS/issues/108 exploit issue-tracking

github.com/...ommit/7329437e1288540336b1c66c114ed3363adcba02 patch

github.com/sanluan/PublicCMS/ product

cve.org (CVE-2026-2010)

nvd.nist.gov (CVE-2026-2010)

Download JSON