Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xibosignage
Xibosignage xibo |
|
| Vendors & Products |
Xibosignage
Xibosignage xibo |
Mon, 31 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view (not change) super admin-restricted module settings and leak the full module entity. Exploitation of the vulnerability is possible on behalf of an authorized user who has access to the Module View feature, which are not granted to non-admins as standard. Users should upgrade to version 4.4.3 which fixes this issue. Upgrading to a fixed version is necessary to remediate. Users unable to upgrade should revoke such privileges from users they do not trust. | |
| Title | Xibo CMS Missing Authorization in Module::settingsForm due to PHP operator precedence | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-31T19:16:46.921Z
Reserved: 2026-06-08T14:00:43.572Z
Link: CVE-2026-52730
No data.
Status : Received
Published: 2026-08-31T20:17:05.427
Modified: 2026-08-31T20:17:05.427
Link: CVE-2026-52730
No data.
OpenCVE Enrichment
Updated: 2026-08-31T21:00:05Z
-
CWE-862
Missing Authorization