CVE-2026-10283
Severity CVSS v4.0:
MEDIUM
Type:
CWE-287
Authentication Issues
Publication date:
01/06/2026
Last modified:
01/06/2026
Description
A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a manipulation results in missing authentication. Remote exploitation of the attack is possible. It is recommended to apply a patch to fix this issue.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
6.50
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/Bottelet/DaybydayCRM/
- https://github.com/Bottelet/DaybydayCRM/issues/348
- https://github.com/Bottelet/DaybydayCRM/pull/363
- https://vuldb.com/cve/CVE-2026-10283
- https://vuldb.com/submit/825442
- https://vuldb.com/submit/825443
- https://vuldb.com/vuln/367576
- https://vuldb.com/vuln/367576/cti



