CVE-2026-92603
- EPSS 0.34%
- Veröffentlicht 16.09.2026 16:03:08
- Zuletzt bearbeitet 24.09.2026 21:08:55
ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message identifiers ...
CVE-2026-80050
- EPSS 0.25%
- Veröffentlicht 25.08.2026 18:23:17
- Zuletzt bearbeitet 24.09.2026 20:43:32
ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file pa...
CVE-2026-3750
- EPSS 0.35%
- Veröffentlicht 08.03.2026 16:32:07
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in ContiNew Admin up to 4.2.0. This issue affects the function URI.create of the file continew-system/src/main/java/top/continew/admin/system/factory/S3ClientFactory.java of the component Storage Management ...
CVE-2025-4552
- EPSS 0.53%
- Veröffentlicht 11.05.2025 23:31:04
- Zuletzt bearbeitet 10.11.2025 15:00:19
A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/system/user/1/password. The manipulation leads to unverified password change. ...
CVE-2025-4551
- EPSS 0.36%
- Veröffentlicht 11.05.2025 23:00:06
- Zuletzt bearbeitet 10.11.2025 15:09:21
A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown function of the file /dev-api/common/file. The manipulation of the argument File leads to cross site scripting. It is possible to la...
CVE-2024-8150
- EPSS 0.53%
- Veröffentlicht 25.08.2024 22:15:05
- Zuletzt bearbeitet 12.09.2024 21:01:57
A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#page of the file /api/system/user?deptId=1&page=1&size=10. The manipula...