Missing Authorization in ChangeWeDer CRM's UserController Component
CVE-2026-92402
5.3MEDIUM
What is CVE-2026-92402?
A vulnerability has been identified in ChangeWeDer CRM, specifically in the UserController component's index function located in UserController.java, leading to missing authorization. This security flaw allows remote attackers to potentially exploit the system without proper authentication due to inadequate access controls. The issue was reported to the project, but a response has yet to be provided. As there is no versioning for the product, detailed information regarding affected and unaffected releases is currently unavailable.
Affected Version(s)
crm c07bd4c97141521af6475034bc58523beed51bbd
