CVE-2026-8737 Details
Description
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler. Executing a manipulation of the argument userId/id can lead to missing authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability in Sanluan PublicCMS version 5.202506.d has been identified within the trade address query functionality. The issue arises in the Trade Address Query Handler, specifically in the execute function of the TradeAddressListDirective file. This vulnerability allows remote, unauthenticated access to sensitive user data by exploiting the lack of proper authentication and authorization checks. Attackers can manipulate userId or address id parameters to access the shipping addresses and phone numbers of other users.
To address this vulnerability, PublicCMS should require authentication for the affected address directives, implement authorization checks to ensure users can only access their own address records, and restrict the client from specifying arbitrary userId values for data retrieval. Additionally, sensitive fields such as phone numbers and addresses should be masked in serialized outputs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 17, 2026CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/809885 | [email protected] | Permission Required |
| https://vuldb.com/vuln/364325 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/364325/cti | [email protected] | AdvisoryPermission Required |
| https://vulnplus-note.wetolink.com/share/VqmGhijVKGBM | [email protected] | ExploitRemedyTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Sanluan PublicCMS | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 17, 2026 | New CVE Received | [email protected] |
Volerion