VYPR

Guns

by Stylefeng

CVEs (2)

  • CVE-2026-92601MedSep 16, 2026
    risk 0.42cvss 6.5epss

    Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated users without assigned roles can exploit this to create, edit, delete, publish and…

  • CVE-2026-92600MedSep 16, 2026
    risk 0.42cvss 6.5epss

    Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC validation for authenticated users. Attackers with…