Unauthorized Database Operations in Toner Management by Raghav
CVE-2026-71252

8.2HIGH

Key Information:

Vendor

Raghav993

Vendor
CVE Published:
5 August 2026

What is CVE-2026-71252?

The toner-management application contains an improper access control vulnerability that allows unauthorized database operations including INSERT, UPDATE, and DELETE. This flaw exists in the admin handlers (add.php, edit.php, delete.php) located in the admin/toners, admin/toner-brands, and admin/printers directories. It enables unauthenticated remote attackers to directly manipulate application data without proper authentication or authorization checks, significantly compromising the integrity of the system. The recent update mandates an authenticated admin session for these operations, addressing this critical security concern.

Affected Version(s)

toner-management 0

toner-management fixed

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Javokhir Tursunboyev
.