CVE-2026-84430
gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 6.0.3 is able to resolve this issue. Upgrading the affected component is advised.
| CWE | CWE-915 CWE-913 |
| Vendor | n/a |
| Product | gouguoa |
| Published | Sep 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a gouguoa
Be the first to know when new medium vulnerabilities affecting n/a gouguoa are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / gouguoa
5.0 5.1 5.2 5.3 5.4 5.5 5.6 5.7 5.8 5.9 5.10.0 6.0.0 6.0.1
References
vuldb.com: https://vuldb.com/vuln/397797 vuldb.com: https://vuldb.com/vuln/397797/cti vuldb.com: https://vuldb.com/cve/CVE-2026-84430 vuldb.com: https://vuldb.com/submit/884061 github.com: https://github.com/Angoddess/CVE/blob/main/README.md gitee.com: https://gitee.com/gouguopen/office/releases/tag/v6.0.3
Credits
๐ Angoddess (VulDB User)