{"id":"CVE-2021-40616","aliases":["GHSA-v25c-8349-v2q3"],"url":"https://o3.security/vulnerability/CVE-2021-40616","summary":"Incorrect Authorization in thinkcmf","details":"thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.","published":"2022-06-14T10:15:17.920Z","modified":"2026-07-09T05:44:59.472185Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"thinkcmf/thinkcmf","fixedVersion":"6.0.0"}],"fix":null,"references":[{"type":"EVIDENCE","url":"https://github.com/thinkcmf/thinkcmf/issues/722"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T05:44:59.472185Z"}}