CVE-2026-8747 PUBLISHED

Z-BlogPHP Commend Approval c_system_event.php CheckComment improper authorization

Assigner: VulDB
Reserved: 16.05.2026 Published: 17.05.2026 Updated: 17.05.2026

A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor n/a
Product Z-BlogPHP
Versions
  • Version 1.7.4.3430 is affected

Credits

  • vulnplusbot (VulDB User) reporter

References

Problem Types

  • Improper Authorization CWE
  • Incorrect Privilege Assignment CWE