Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authenticated users to move other users' threads. Attackers can send crafted threadId and forumId values to /message/threadToForum/save to relocate any reply-less thread into an arbitrary forum.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authenticated users to move other users' threads. Attackers can send crafted threadId and forumId values to /message/threadToForum/save to relocate any reply-less thread into an arbitrary forum. | |
| Title | Jivejdon through commit ee67a65e Missing Authorization via /message/threadToForum/save Thread Move | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T21:51:28.044Z
Reserved: 2026-10-08T20:54:05.620Z
Link: CVE-2026-107792
No data.
Status : Received
Published: 2026-10-08T22:17:29.293
Modified: 2026-10-08T22:17:29.293
Link: CVE-2026-107792
No data.
OpenCVE Enrichment
Updated: 2026-10-09T00:30:17Z
Weaknesses