Executive brief
A security flaw exists in the Gobito Corporate Training Management System, a platform used by organizations to manage employee education and training programs. The system incorrectly relies on the user's web browser to enforce security rules that should be handled by the server. This allows an authenticated user to bypass certain restrictions and manipulate data, potentially leading to unauthorized changes in training records or system information.
Technical details
The Gobito Corporate Training Management System is vulnerable to CWE-602 (Client-Side Enforcement of Server-Side Security). The application relies on client-side controls to validate or restrict data that should be strictly enforced on the server. An authenticated attacker with network access can bypass these client-side checks to perform unauthorized input data manipulation. The vulnerability is present in versions prior to the commit dd1a9df64. Exploitation allows for unauthorized integrity changes (I:L) but does not impact confidentiality or availability according to the reported CVSS vector.
Affected products
- Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System before dd1a9df64
Timeline
- 2026-07-20: advisory: NVD publication date