Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Apr 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sanluan
Sanluan publiccms |
|
| Vendors & Products |
Sanluan
Sanluan publiccms |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the component Failed Login Handler. This manipulation of the argument errorPassword causes cleartext storage in a file or on disk. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Sanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in file | |
| First Time appeared |
Publiccms
Publiccms publiccms |
|
| Weaknesses | CWE-312 CWE-313 |
|
| CPEs | cpe:2.3:a:publiccms:publiccms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Publiccms
Publiccms publiccms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-21T20:40:36.437Z
Reserved: 2026-04-21T14:35:38.865Z
Link: CVE-2026-6796
Updated: 2026-04-21T20:40:26.846Z
Status : Deferred
Published: 2026-04-21T21:16:48.333
Modified: 2026-04-22T20:22:50.570
Link: CVE-2026-6796
No data.
OpenCVE Enrichment
Updated: 2026-04-22T05:30:09Z