CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. See the original NVD description below for full technical details.
CVE
CVE-2026-48941
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%
Original NVD Description
The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/`
Related CVEs
Other vulnerabilities affecting the same vendor(s)