Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Versions 1.41.1 and 2.41.1 contain a patch.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Versions 1.41.1 and 2.41.1 contain a patch. | |
| Title | Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-23T21:37:49.083Z
Reserved: 2026-03-11T21:16:21.658Z
Link: CVE-2026-32299
No data.
Status : Received
Published: 2026-03-23T22:16:27.780
Modified: 2026-03-23T22:16:27.780
Link: CVE-2026-32299
No data.
OpenCVE Enrichment
No data.