MRCMS 3.1.2 contains an access control vulnerability. The...
Critical severity
Unreviewed
Published
Apr 7, 2026
to the GitHub Advisory Database
•
Updated Apr 9, 2026
Description
Published by the National Vulnerability Database
Apr 7, 2026
Published to the GitHub Advisory Database
Apr 7, 2026
Last updated
Apr 9, 2026
MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks proper authorization validation, enabling direct addition of super administrator accounts without authentication.
References