{"id":"GHSA-4vrc-q7m6-vq7w","summary":"Lin CMS vulnerable to Improper Authentication","details":"An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.","aliases":["CVE-2022-44244","PYSEC-2026-839"],"modified":"2026-07-07T11:56:04.857574305Z","published":"2022-11-10T12:01:09Z","database_specific":{"github_reviewed_at":"2022-11-22T00:18:48Z","nvd_published_at":"2022-11-09T22:15:00Z","cwe_ids":["CWE-287"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-44244"},{"type":"WEB","url":"https://gist.github.com/cai-niao98/58c97899695488bd73a73d56adf44c4c"},{"type":"PACKAGE","url":"https://github.com/TaleLin/lin-cms-flask"},{"type":"WEB","url":"https://github.com/cai-niao98/lin-cms"}],"affected":[{"package":{"name":"lin-cms","ecosystem":"PyPI","purl":"pkg:pypi/lin-cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.2.1"}]}],"versions":["0.1.1a1","0.1.1a2","0.1.1a3","0.1.1a4","0.1.1a5","0.1.1a6","0.1.1a7","0.1.1a8","0.1.1b1","0.1.1b2","0.1.1b3","0.1.1b4","0.2.0b1","0.2.0b2","0.2.0b3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-4vrc-q7m6-vq7w/GHSA-4vrc-q7m6-vq7w.json"}},{"package":{"name":"io.github.talelin:lin-cms-core","ecosystem":"Maven","purl":"pkg:maven/io.github.talelin/lin-cms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.2.1"}]}],"versions":["0.0.1-RC1","0.0.1-RC2","0.0.1-RC3","0.0.1-RC4","0.0.1-RC5","0.0.1-RC6","0.1.0-RELEASE","0.1.1-RC1","0.1.1-RC2","0.1.1-RC3","0.2.0-RC1","0.2.0-RC2","0.2.0-RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-4vrc-q7m6-vq7w/GHSA-4vrc-q7m6-vq7w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}