token of the file /api/users of the component API endpoint. Executing a manipulation of the argument User can lead to permission issues.This vulnerability is registered as CVE-2026-12593. It is possible to launch the attack remotely. No exploit is available.
SOCIAL SHARE CARD GENERATOR