Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 and 2.41.1 contain a patch.
References
Configurations
Configuration 1 (hide)
|
History
24 Mar 2026, 20:40
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:* | |
| First Time |
Opensource-workshop connect-cms
Opensource-workshop |
|
| References | () https://github.com/opensource-workshop/connect-cms/commit/7c9951738c62a1d51b91e9956d1eb756c5d52cce - Patch | |
| References | () https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1 - Release Notes | |
| References | () https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1 - Release Notes | |
| References | () https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-qr6x-wvxr-8hm9 - Vendor Advisory |
23 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-23 22:16
Updated : 2026-03-24 20:40
NVD link : CVE-2026-32300
Mitre link : CVE-2026-32300
CVE.ORG link : CVE-2026-32300
JSON object : View
Products Affected
opensource-workshop
- connect-cms
