Unauthorized Database Operations in Toner Management by Raghav
CVE-2026-71252
8.2HIGH
What is CVE-2026-71252?
The toner-management application contains an improper access control vulnerability that allows unauthorized database operations including INSERT, UPDATE, and DELETE. This flaw exists in the admin handlers (add.php, edit.php, delete.php) located in the admin/toners, admin/toner-brands, and admin/printers directories. It enables unauthenticated remote attackers to directly manipulate application data without proper authentication or authorization checks, significantly compromising the integrity of the system. The recent update mandates an authenticated admin session for these operations, addressing this critical security concern.
Affected Version(s)
toner-management 0
toner-management fixed
