| 概要 | The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups. |
|---|---|
| 公表日 | 2026年5月19日19:16 |
| 登録日 | 2026年5月20日4:12 |
| 最終更新日 | 2026年5月19日23:47 |