GHSA-23hh-2f47-3p4h

Suggest an improvement
Source
https://github.com/advisories/GHSA-23hh-2f47-3p4h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-23hh-2f47-3p4h/GHSA-23hh-2f47-3p4h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-23hh-2f47-3p4h
Aliases
  • CVE-2026-1193
Published
2026-01-20T00:30:27Z
Modified
2026-09-10T03:50:32Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
MineAdmin has Incorrect Privilege Assignment
Details

A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids": [
        "CWE-266"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-02-05T22:00:27Z",
    "nvd_published_at": "2026-01-19T23:16:03Z",
    "severity": "LOW"
}
References

Affected packages

Packagist / mineadmin/mineadmin

Package

Name
mineadmin/mineadmin
Purl
pkg:composer/mineadmin/mineadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Last Affected
2.0.3

Affected versions

v1.*
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.*
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
2.*
2.0.0-alpha.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-23hh-2f47-3p4h/GHSA-23hh-2f47-3p4h.json"