<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cwe-862 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-862/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-862/index.xml" rel="self" type="application/rss+xml"/><item><title>MISP Core `deleteSelection` Broken Access Control — Bulk Deletion of Foreign Event Reports &amp; Sharing Groups (CVE-2026-56423)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56423-misp-core-deleteselection-broken-access-control/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56423-misp-core-deleteselection-broken-access-control/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-56423. Status: Weaponized — contributor-level bulk hard-delete of a foreign organizations Event Report confirmed against a real MISP core build; denied on the patched build. Affects: MISP (Malware Information Sharing Platform) Core — EventReportsController::deleteSelection and SharingGroupsController::deleteSelection. Tags: misp, misp-core, broken-access-control, cwe-862, bulk-deletion, authenticated, threat-intel-platform.</description><category>web</category><category>High</category><category>misp</category><category>misp-core</category><category>broken-access-control</category><category>cwe-862</category><category>bulk-deletion</category><category>authenticated</category><category>threat-intel-platform</category></item><item><title>Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-57830-joomla-helix-ultimate-file-deletion/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-57830-joomla-helix-ultimate-file-deletion/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-57830. Status: Weaponized. Affects: Helix Ultimate Framework (plg_system_helixultimate), the JoomShaper Joomla template framework bundled with virtually every JoomShaper Joomla template. Tags: joomla, helix-ultimate, joomshaper, arbitrary-file-deletion, cwe-862, unauthenticated, csrf-token-only-check.</description><category>web</category><category>Critical</category><category>joomla</category><category>helix-ultimate</category><category>joomshaper</category><category>arbitrary-file-deletion</category><category>cwe-862</category><category>unauthenticated</category><category>csrf-token-only-check</category></item><item><title>XWiki Unauthenticated XAR Import Leading to RCE — CVE-2026-33137</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33137-xwiki-xar-import-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33137-xwiki-xar-import-rce/</guid><description>Critical severity (CVSS 9.3) — web · CVE-2026-33137. Status: Weaponized. Affects: XWiki Platform. Tags: xwiki, rce, missing-authorization, xar-import, groovy, velocity, unauthenticated, cwe-862.</description><category>web</category><category>Critical</category><category>xwiki</category><category>rce</category><category>missing-authorization</category><category>xar-import</category><category>groovy</category><category>velocity</category><category>unauthenticated</category><category>cwe-862</category></item><item><title>User Registration &amp; Membership for WordPress — Unauthenticated Admin Approval Bypass (CVE-2026-6145)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6145-user-registration-wp-admin-approval-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6145-user-registration-wp-admin-approval-bypass/</guid><description>Medium severity (CVSS 5.3) — web · CVE-2026-6145. Status: Weaponized. Affects: User Registration &amp; Membership for WordPress plugin. Tags: wordpress, missing-authorization, admin-approval-bypass, user-registration, cwe-862.</description><category>web</category><category>Medium</category><category>wordpress</category><category>missing-authorization</category><category>admin-approval-bypass</category><category>user-registration</category><category>cwe-862</category></item><item><title>JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49048-joomcck-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49048-joomcck-sqli/</guid><description>Critical severity (CVSS 8.7) — web · CVE-2026-49048 (Advisory ID JOOMCCK-2026-001). Status: PoC. Affects: JoomCCK (com_joomcck) — Content Construction Kit extension for Joomla, by JoomCoder. Tags: joomla, joomcck, com_joomcck, sql-injection, cwe-89, missing-authorization, cwe-862, unauthenticated, blind-sqli, union-based.</description><category>web</category><category>Critical</category><category>joomla</category><category>joomcck</category><category>com_joomcck</category><category>sql-injection</category><category>cwe-89</category><category>missing-authorization</category><category>cwe-862</category><category>unauthenticated</category><category>blind-sqli</category><category>union-based</category></item><item><title>Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40776-eventin-broken-access-control/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40776-eventin-broken-access-control/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-40776 / Patchstack PSID 85de025d71e7. Status: PoC. Affects: Eventin — Events Calendar, Event Booking, Ticket &amp; Registration (wp-event-solution WordPress plugin). Tags: wordpress, wordpress-plugin, broken-access-control, idor, nonce-misuse, cwe-862, pii-disclosure, unauthenticated.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-plugin</category><category>broken-access-control</category><category>idor</category><category>nonce-misuse</category><category>cwe-862</category><category>pii-disclosure</category><category>unauthenticated</category></item><item><title>Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54415-azuriom-account-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54415-azuriom-account-takeover/</guid><description>High severity (CVSS 3.1) — web · CVE-2026-54415. Status: PoC. Affects: Azuriom CMS. Tags: azuriom, cms, broken-access-control, cwe-862, cwe-269, privilege-escalation, account-takeover, php, laravel, azlink.</description><category>web</category><category>High</category><category>azuriom</category><category>cms</category><category>broken-access-control</category><category>cwe-862</category><category>cwe-269</category><category>privilege-escalation</category><category>account-takeover</category><category>php</category><category>laravel</category><category>azlink</category></item><item><title>AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30950-autogpt-session-idor/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30950-autogpt-session-idor/</guid><description>High severity (CVSS 7.1) — web · CVE-2026-30950 (GHSA-q58p-v9r9-7gqj). Status: PoC. Affects: AutoGPT Platform (autogpt-platform-backend, chat/copilot feature). Tags: autogpt, idor, cwe-862, session-hijack, missing-authorization, python, fastapi, redis.</description><category>web</category><category>High</category><category>autogpt</category><category>idor</category><category>cwe-862</category><category>session-hijack</category><category>missing-authorization</category><category>python</category><category>fastapi</category><category>redis</category></item></channel></rss>