๐Ÿ” CVE Alert

CVE-2026-84430

MEDIUM 6.3

gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 6.0.3 is able to resolve this issue. Upgrading the affected component is advised.

CWE CWE-915 CWE-913
Vendor n/a
Product gouguoa
Published Sep 2, 2026
Stay Ahead of the Next One

Get instant alerts for n/a gouguoa

Be the first to know when new medium vulnerabilities affecting n/a gouguoa are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / gouguoa
5.0 5.1 5.2 5.3 5.4 5.5 5.6 5.7 5.8 5.9 5.10.0 6.0.0 6.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/397797 vuldb.com: https://vuldb.com/vuln/397797/cti vuldb.com: https://vuldb.com/cve/CVE-2026-84430 vuldb.com: https://vuldb.com/submit/884061 github.com: https://github.com/Angoddess/CVE/blob/main/README.md gitee.com: https://gitee.com/gouguopen/office/releases/tag/v6.0.3

Credits

๐Ÿ” Angoddess (VulDB User)