Unauthorized Message Modification in CRMEB by CRMEB Team
CVE-2026-85177
5.3MEDIUM
What is CVE-2026-85177?
CRMEB versions up to 6.0.0 include a vulnerability in the edit_message handler of MessageSystemController.php that fails to validate message ownership effectively. This oversight allows authenticated users to manipulate arbitrary system inbox messages. Attackers are able to alter message properties, such as marking messages as read or deleting them without proper authorization, leading to potential misinformation and privacy concerns among users.
Affected Version(s)
CRMEB 0 <= 6.0.0
