Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52730— Xibo CMS Missing Authorization in Module::settingsForm due to PHP operator precedence

Quick assessment

Affected
xibosignage xibo-cms
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Xibo 是一个开源的数字标牌平台,包含基于 Web 的内容管理系统和 Windows 显示播放器软件。在 4.4.3 版本之前, 中缺少对权限(Authorization)的校验,导致拥有“模块查看”权限的用户能够查看(而非修改)仅限超级管理员访问的模块设置,并泄露完整的模块实体信息。该漏洞可被任何拥有“模块查看”权限的授权用户利用;该权限默认并不授予非管理员用户。建议用户升级至 4.4.3 版本以修复此问题,升级至修复版本是必要的缓解措施。若无法升级的用户,应从不受信任的用户处撤销相应权限。

CVSS 4.3 · Medium

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services

Affected Version Matrix 1

VendorProduct Version RangeStatus
xibosignage xibo-cms < 4.4.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52730

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Xibo CMS Missing Authorization in Module::settingsForm due to PHP operator precedence
Source: CVE Program / CVE List V5
Vulnerability Description
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view (not change) super admin-restricted module settings and leak the full module entity. Exploitation of the vulnerability is possible on behalf of an authorized user who has access to the Module View feature, which are not granted to non-admins as standard. Users should upgrade to version 4.4.3 which fixes this issue. Upgrading to a fixed version is necessary to remediate. Users unable to upgrade should revoke such privileges from users they do not trust.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
xibosignage xibo-cms < 4.4.3 -

II. Public POCs for CVE-2026-52730

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52730

登录查看更多情报信息。

Other References for CVE-2026-52730 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-52730

No comments yet


Leave a comment