CVE-2026-84430 | gouguoa up to 5.10.0/6.0.1 edit_personal Endpoint Index.php update position_id dynamically-determined object attributes
A vulnerability classified as critical was found in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes.
This vulnerability is documented as CVE-2026-84430. The attack can be executed remotely. Additionally, an exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More