CVE-2026-71252
toner-management: Unauthenticated State-Changing Admin Actions
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization check, while access control was enforced only in listing views. An unauthenticated remote attacker could invoke these handlers directly to create, modify, or destroy application data. The vendor has since merged a fix requiring an authenticated admin session before any such handler proceeds.
| CWE | CWE-862 |
| Vendor | raghav993 |
| Product | toner-management |
| Published | Aug 5, 2026 |
| Last Updated | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for raghav993 toner-management
Be the first to know when new high vulnerabilities affecting raghav993 toner-management are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
raghav993 / toner-management
0
References
Credits
Javokhir Tursunboyev